Skip to content

[Snyk] Security upgrade request from 2.79.0 to 2.88.2#16

Open
taysmith-test wants to merge 1 commit intomasterfrom
snyk-fix-3b381a17453b285c835c4bfbc6da4f47
Open

[Snyk] Security upgrade request from 2.79.0 to 2.88.2#16
taysmith-test wants to merge 1 commit intomasterfrom
snyk-fix-3b381a17453b285c835c4bfbc6da4f47

Conversation

@taysmith-test
Copy link
Copy Markdown
Owner

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `yarn` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json
    • yarn.lock

Note for zero-installs users

If you are using the Yarn feature zero-installs that was introduced in Yarn V2, note that this PR does not update the .yarn/cache/ directory meaning this code cannot be pulled and immediately developed on as one would expect for a zero-install project - you will need to run yarn to update the contents of the ./yarn/cache directory.
If you are not using zero-install you can ignore this as your flow should likely be unchanged.

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 584/1000
Why? Has a fix available, CVSS 7.4
Regular Expression Denial of Service (ReDoS)
SNYK-JS-HAWK-2808852
No No Known Exploit
high severity 696/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
Regular Expression Denial of Service (ReDoS)
SNYK-JS-ISMYJSONVALID-597165
No Proof of Concept
high severity 686/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.3
Arbitrary Code Execution
SNYK-JS-ISMYJSONVALID-597167
No Proof of Concept
medium severity 601/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 5.6
Prototype Pollution
SNYK-JS-JSONPOINTER-1577288
No Proof of Concept
critical severity 811/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 9.8
Prototype Pollution
SNYK-JS-JSONPOINTER-598804
No Proof of Concept
high severity 644/1000
Why? Has a fix available, CVSS 8.6
Prototype Pollution
SNYK-JS-JSONSCHEMA-1920922
No No Known Exploit
high severity 696/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
Prototype Poisoning
SNYK-JS-QS-3153490
No Proof of Concept
medium severity 636/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 6.3
Prototype Pollution
npm:hoek:20180212
No Proof of Concept
low severity 571/1000
Why? Mature exploit, Has a fix available, CVSS 3.7
Regular Expression Denial of Service (ReDoS)
npm:is-my-json-valid:20180214
No Mature
high severity 589/1000
Why? Has a fix available, CVSS 7.5
Prototype Override Protection Bypass
npm:qs:20170213
No No Known Exploit
medium severity 646/1000
Why? Mature exploit, Has a fix available, CVSS 5.2
Uninitialized Memory Exposure
npm:stringstream:20180511
No Mature
medium severity 576/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 5.1
Uninitialized Memory Exposure
npm:tunnel-agent:20170305
No Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Regular Expression Denial of Service (ReDoS)
🦉 Arbitrary Code Execution
🦉 Prototype Pollution
🦉 More lessons are available in Snyk Learn

@@ -27,7 +27,7 @@
"finalhandler": "^0.4.1",
"morgan": "^1.7.0",
Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

morgan 1.7.0 / package.json

Total vulnerabilities: 4

Critical: 1 High: 1 Medium: 2 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2019-5413 CRITICAL CRITICAL 9.8 1.9.1 Open
CVE-2017-20165 HIGH HIGH 7.5 - Open
CVE-2017-16137 MEDIUM MEDIUM 5.3 - Open
CVE-2017-20162 MEDIUM MEDIUM 5.3 - Open

"morgan": "^1.7.0",
"prom-client": "^6.3.0",
"request": "^2.72.0",
"request": "^2.88.2",
Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

finalhandler 0.4.1 / package.json

Total vulnerabilities: 3

Critical: 0 High: 1 Medium: 2 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2017-20165 HIGH HIGH 7.5 - Open
CVE-2017-16137 MEDIUM MEDIUM 5.3 - Open
CVE-2017-20162 MEDIUM MEDIUM 5.3 - Open

"morgan": "^1.7.0",
"prom-client": "^6.3.0",
"request": "^2.72.0",
"request": "^2.88.2",
Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

request 2.88.2 / package.json

Total vulnerabilities: 2

Critical: 2 High: 0 Medium: 0 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2021-3918 CRITICAL CRITICAL 9.8 - Open
CVE-2023-26136 CRITICAL CRITICAL 9.8 - Open

"prom-client": "^6.3.0",
"request": "^2.72.0",
"request": "^2.88.2",
"serve-static": "1.12.6"
Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

serve-static 1.12.6 / package.json

Total vulnerabilities: 1

Critical: 0 High: 1 Medium: 0 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2017-16138 HIGH HIGH 7.5 - Open

"morgan": "^1.7.0",
"prom-client": "^6.3.0",
"request": "^2.72.0",
"request": "^2.88.2",
Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

verror 1.3.6 / package.json

LOW  Unknown License (NOT_FOUND)

This package use a non-SPDX, unrecognized, or private open-source license. Ensure this package is compliant.

"morgan": "^1.7.0",
"prom-client": "^6.3.0",
"request": "^2.72.0",
"request": "^2.88.2",
Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

bintrees 1.0.1 / package.json

LOW  Unknown License (NOT_FOUND)

This package use a non-SPDX, unrecognized, or private open-source license. Ensure this package is compliant.

"morgan": "^1.7.0",
"prom-client": "^6.3.0",
"request": "^2.72.0",
"request": "^2.88.2",
Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

extsprintf 1.0.2 / package.json

LOW  Unknown License (NOT_FOUND)

This package use a non-SPDX, unrecognized, or private open-source license. Ensure this package is compliant.

"morgan": "^1.7.0",
"prom-client": "^6.3.0",
"request": "^2.72.0",
"request": "^2.88.2",
Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

formatio 1.1.1 / package.json

LOW  Unknown License (NOT_FOUND)

This package use a non-SPDX, unrecognized, or private open-source license. Ensure this package is compliant.

"morgan": "^1.7.0",
"prom-client": "^6.3.0",
"request": "^2.72.0",
"request": "^2.88.2",
Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

formidable 1.0.17 / package.json

LOW  Unknown License (NOT_FOUND)

This package use a non-SPDX, unrecognized, or private open-source license. Ensure this package is compliant.

"morgan": "^1.7.0",
"prom-client": "^6.3.0",
"request": "^2.72.0",
"request": "^2.88.2",
Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

ms 0.7.1 / package.json

LOW  Unknown License (NOT_FOUND)

This package use a non-SPDX, unrecognized, or private open-source license. Ensure this package is compliant.

"morgan": "^1.7.0",
"prom-client": "^6.3.0",
"request": "^2.72.0",
"request": "^2.88.2",
Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

optimist 0.6.1 / package.json

MEDIUM  Noncompliant License (X11)

This package contains a license that is not OSI-approved.

"morgan": "^1.7.0",
"prom-client": "^6.3.0",
"request": "^2.72.0",
"request": "^2.88.2",
Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

samsam 1.1.2 / package.json

LOW  Unknown License (NOT_FOUND)

This package use a non-SPDX, unrecognized, or private open-source license. Ensure this package is compliant.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants