Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Fix for 38 vulnerabilities #1

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

DaniellaNiceSnyk
Copy link
Owner

Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

As this is a private repository, Snyk-bot does not have access. Therefore, this PR has been created automatically, but appears to have been created by a real user.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:

    • package.json
    • package-lock.json
  • Adding or updating a Snyk policy (.snyk) file; this file is required in order to apply Snyk vulnerability patches.
    Find out more.

Vulnerabilities that will be fixed

With an upgrade:
Severity Issue Breaking Change Exploit Maturity
high severity Denial of Service (DoS)
SNYK-JS-EXPRESSFILEUPLOAD-473997
Yes No Known Exploit
medium severity Prototype Pollution
SNYK-JS-JQUERY-174006
Yes No Known Exploit
high severity Prototype Pollution
SNYK-JS-LODASH-450202
No Proof of Concept
high severity Prototype Pollution
SNYK-JS-LODASH-73638
No No Known Exploit
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-LODASH-73639
No No Known Exploit
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-MARKED-174116
No No Known Exploit
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-MARKED-451540
No No Known Exploit
high severity Denial of Service (DoS)
SNYK-JS-MONGODB-473855
Yes No Known Exploit
medium severity Information Exposure
SNYK-JS-MONGOOSE-472486
Yes No Known Exploit
medium severity Prototype Pollution
SNYK-JS-YARGSPARSER-560381
Yes Proof of Concept
high severity Arbitrary File Write via Archive Extraction (Zip Slip)
npm:adm-zip:20180415
No Mature
low severity Regular Expression Denial of Service (ReDoS)
npm:debug:20170905
No No Known Exploit
high severity Code Injection
npm:dustjs-linkedin:20160819
No No Known Exploit
high severity Arbitrary Code Execution
npm:ejs:20161128
Yes No Known Exploit
medium severity Cross-site Scripting (XSS)
npm:ejs:20161130
Yes No Known Exploit
medium severity Denial of Service (DoS)
npm:ejs:20161130-1
Yes No Known Exploit
high severity Regular Expression Denial of Service (ReDoS)
npm:fresh:20170908
No No Known Exploit
medium severity Cross-site Scripting (XSS)
npm:jquery:20150627
Yes No Known Exploit
medium severity Prototype Pollution
npm:lodash:20180130
No No Known Exploit
high severity Cross-site Scripting (XSS)
npm:marked:20150520
No No Known Exploit
high severity Cross-site Scripting (XSS)
npm:marked:20170112
No No Known Exploit
high severity Cross-site Scripting (XSS)
npm:marked:20170815
No No Known Exploit
medium severity Cross-site Scripting (XSS)
npm:marked:20170815-1
No No Known Exploit
high severity Regular Expression Denial of Service (ReDoS)
npm:marked:20170907
No No Known Exploit
high severity Regular Expression Denial of Service (ReDoS)
npm:marked:20180225
No Proof of Concept
medium severity Denial of Service (DoS)
npm:mem:20180117
Yes No Known Exploit
low severity Regular Expression Denial of Service (ReDoS)
npm:mime:20170907
Yes No Known Exploit
medium severity Regular Expression Denial of Service (ReDoS)
npm:moment:20161019
No No Known Exploit
low severity Regular Expression Denial of Service (ReDoS)
npm:moment:20170905
No No Known Exploit
medium severity Remote Memory Exposure
npm:mongoose:20160116
No Mature
low severity Regular Expression Denial of Service (ReDoS)
npm:ms:20170412
Yes No Known Exploit
high severity Regular Expression Denial of Service (ReDoS)
npm:negotiator:20160616
Yes No Known Exploit
high severity Uninitialized Memory Exposure
npm:npmconf:20180512
Yes Mature
high severity Prototype Override Protection Bypass
npm:qs:20170213
No No Known Exploit
medium severity Regular Expression Denial of Service (ReDoS)
npm:semver:20150403
Yes No Known Exploit
medium severity Directory Traversal
npm:st:20140206
No No Known Exploit
medium severity Open Redirect
npm:st:20171013
Yes Mature
Commit messages
Package name: adm-zip The new version differs by 50 commits.
  • 80d259f Version bump
  • 3f00a03 Fixed #176
  • 650e752 Fixed wrong date on files (issue #203)
  • d01fa8c Fixed bugs introduced with 0.4.9
  • c0cc85d Merge pull request #219 from jontore/master
  • 39c83a2 Merge pull request #209 from poshta1900/fix
  • b94c5dd Merge pull request #227 from hhaidar/master
  • c95c553 Merge pull request #228 from jmcollin78/patch-1
  • cda668c Fix issue #218
  • 0f2cb41 Fix octal literals so they work in strict mode
  • 888931d To support strict mode use 0o prefix to octal numbers
  • 89b6f67 Update package.json
  • 9592298 Update README.md
  • ce59e5a Merge pull request #215 from grnd/master
  • 38cb4a4 fix: resolve both target and entry path
  • 18c3d31 Update package.json
  • 666adec Update package.json
  • 499d59b Update package.json
  • 62f6400 Merge pull request #212 from aviadatsnyk/master
  • 6f4dfeb fix: prevent extracting archived files outside of target path
  • ef0abe6 add try-catch around fs.writeSync
  • e116bc1 Merge pull request #208 from pmuens/patch-1
  • 12d2099 Fix data accessing example in README
  • 032566b Merge pull request #204 from BridgeAR/master

See the full diff

Package name: body-parser The new version differs by 221 commits.

See the full diff

Package name: errorhandler The new version differs by 85 commits.

See the full diff

Package name: express The new version differs by 250 commits.

See the full diff

Package name: marked The new version differs by 250 commits.
  • 529a8d4 Merge pull request #1441 from styfle/release-0.6.2
  • fc5dbf1 🗜️ minify [skip ci]
  • b1ddd3c Merge pull request #1460 from andersk/inline-text-quadratic
  • be27472 Improve worst-case performance of inline.text regex
  • 6b88601 0.6.2
  • ba1de1e 🗜️ minify [skip ci]
  • d94253c Merge pull request #1438 from UziTech/html-new-line-fix
  • 6eec528 Merge pull request #1449 from UziTech/use-htmldiffer
  • 0cd0333 remove redundant comments
  • ff127c5 use template literals
  • a16251d fix test spacing
  • da57301 use htmldiffer in file tests & update to node 4
  • 621f649 abstract htmldiffer
  • 42e816c fix again
  • 246dd3d fix whitespace after tag
  • f1089fe add test
  • 0f0b763 allow html without \n after
  • d069d0d Merge pull request #1448 from UziTech/version
  • 5d6bde0 Merge pull request #1444 from UziTech/normalize-tests
  • 4760772 fix tests
  • df310a8 remove header ids from original tests
  • 775d08d move redos tests to /redos folder
  • b169e7b add excerpt length constant
  • fd9dc21 update deps

See the full diff

Package name: mongoose The new version differs by 250 commits.
  • 40a879b chore: release 5.7.5
  • 159457d chore: add vpn black friday as sponsor
  • e6285ea Merge pull request #8244 from AbdelrahmanHafez/master
  • d9163f5 fix: correct order for declaration
  • cec9dda Minor refactor to ValidationError
  • 13ae085 docs(index): add favicon to home page
  • 96ce0eb style: fix lint
  • 973b1e0 docs: add schema options to API docs
  • cdfb507 chore: add useUnifiedTopology for tests re: #8212
  • 936ddfb fix(update): handle subdocument pre('validate') errors in update validation
  • 98b3b09 test(update): repro #7187
  • b9c1012 docs(middleware): add note about accessing the document being updated in pre('findOneAndUpdate')
  • 327b47a fix(subdocument): make subdocument#isModified use parent document's isModified
  • 54db026 test(subdocument): repro #8223
  • 89eb449 chore: now working on 5.7.5
  • ffbff22 chore: change version for recompiling website
  • 0562ca7 chore: add opencollective sponsors: top web design companies, casino top
  • ee22c09 chore: now working on 5.7.5
  • f3eca5b fix(query): delete top-level `_bsontype` property in queries to prevent silent empty queries
  • cc10e0d test(query): repro #8222
  • ede5aef chore: release 5.7.4
  • 402db1a fix(model): support passing `options` to `Model.remove()`
  • 7a20276 fix(schema): handle `required: null` and `required: undefined` as `required: false`
  • 9b4a323 test(schema): repro #8219

See the full diff

Package name: ms The new version differs by 19 commits.
  • 9b88d15 2.0.0
  • 94b995c Invalidated cache for slack badge
  • bcf5715 Bumped dependencies to the latest version
  • b1eaab7 Ignored logs coming from npm
  • caae298 Limit str to 100 to avoid ReDoS of 0.3s (#89)
  • b83b36d chore(package): update eslint to version 3.19.0 (#88)
  • 3f2a4d7 chore(package): update husky to version 0.13.3 (#86)
  • 7daf984 1.0.0
  • ee91f30 More suitable name for file containing tests
  • e818c35 Removed browser testing
  • c9b1fd3 Test on LTS version of Node
  • 389840b Badge for XO removed
  • 1fbbe97 Removed component specification
  • 57b3ef8 Use `prettier` and `eslint`
  • 94068ea Removed XO
  • 4b7f48f chore(package): update serve to version 5.0.4 (#85)
  • bd49cec chore(package): update xo to version 0.18.0 (#84)
  • d4a94b1 chore(package): update serve to version 5.0.3 (#83)
  • 923eee1 chore(package): update serve to version 5.0.2 (#82)

See the full diff

Package name: tap The new version differs by 110 commits.

See the full diff

With a Snyk patch:
Severity Issue Exploit Maturity
medium severity Regular Expression Denial of Service (ReDoS)
npm:ms:20151024
No Known Exploit

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:

🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic

The following vulnerabilities are fixed with an upgrade:
- https://snyk.io/vuln/SNYK-JS-EXPRESSFILEUPLOAD-473997
- https://snyk.io/vuln/SNYK-JS-JQUERY-174006
- https://snyk.io/vuln/SNYK-JS-LODASH-450202
- https://snyk.io/vuln/SNYK-JS-LODASH-73638
- https://snyk.io/vuln/SNYK-JS-LODASH-73639
- https://snyk.io/vuln/SNYK-JS-MARKED-174116
- https://snyk.io/vuln/SNYK-JS-MARKED-451540
- https://snyk.io/vuln/SNYK-JS-MONGODB-473855
- https://snyk.io/vuln/SNYK-JS-MONGOOSE-472486
- https://snyk.io/vuln/SNYK-JS-YARGSPARSER-560381
- https://snyk.io/vuln/npm:adm-zip:20180415
- https://snyk.io/vuln/npm:debug:20170905
- https://snyk.io/vuln/npm:dustjs-linkedin:20160819
- https://snyk.io/vuln/npm:ejs:20161128
- https://snyk.io/vuln/npm:ejs:20161130
- https://snyk.io/vuln/npm:ejs:20161130-1
- https://snyk.io/vuln/npm:fresh:20170908
- https://snyk.io/vuln/npm:jquery:20150627
- https://snyk.io/vuln/npm:lodash:20180130
- https://snyk.io/vuln/npm:marked:20150520
- https://snyk.io/vuln/npm:marked:20170112
- https://snyk.io/vuln/npm:marked:20170815
- https://snyk.io/vuln/npm:marked:20170815-1
- https://snyk.io/vuln/npm:marked:20170907
- https://snyk.io/vuln/npm:marked:20180225
- https://snyk.io/vuln/npm:mem:20180117
- https://snyk.io/vuln/npm:mime:20170907
- https://snyk.io/vuln/npm:moment:20161019
- https://snyk.io/vuln/npm:moment:20170905
- https://snyk.io/vuln/npm:mongoose:20160116
- https://snyk.io/vuln/npm:ms:20170412
- https://snyk.io/vuln/npm:negotiator:20160616
- https://snyk.io/vuln/npm:npmconf:20180512
- https://snyk.io/vuln/npm:qs:20170213
- https://snyk.io/vuln/npm:semver:20150403
- https://snyk.io/vuln/npm:st:20140206
- https://snyk.io/vuln/npm:st:20171013


The following vulnerabilities are fixed with a Snyk patch:
- https://snyk.io/vuln/npm:ms:20151024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants