Skip to content

[Snyk] Upgrade express from 4.18.1 to 4.21.2 - #162

Open
IvanCastroDev wants to merge 1 commit into
mainfrom
snyk-upgrade-18d8500c15924bc90919f5a834d96ced
Open

[Snyk] Upgrade express from 4.18.1 to 4.21.2#162
IvanCastroDev wants to merge 1 commit into
mainfrom
snyk-upgrade-18d8500c15924bc90919f5a834d96ced

Conversation

@IvanCastroDev

Copy link
Copy Markdown
Owner

snyk-top-banner

Snyk has created this PR to upgrade express from 4.18.1 to 4.21.2.

ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.


  • The recommended version is 9 versions ahead of your current version.

  • The recommended version was released 3 months ago.

Issues fixed by the recommended upgrade:

IssueScoreExploit Maturity
high severityAsymmetric Resource Consumption (Amplification)
SNYK-JS-BODYPARSER-7926860
624No Known Exploit
high severityServer-side Request Forgery (SSRF)
SNYK-JS-IP-6240864
624Proof of Concept
high severityPrototype Pollution
SNYK-JS-MONGOOSE-2961688
624Proof of Concept
high severityPrototype Pollution
SNYK-JS-MONGOOSE-5777721
624Proof of Concept
high severityImproper Neutralization of Special Elements in Data Query Logic
SNYK-JS-MONGOOSE-8446504
624No Known Exploit
high severityImproper Neutralization of Special Elements in Data Query Logic
SNYK-JS-MONGOOSE-8623536
624No Known Exploit
medium severityCross-site Scripting (XSS)
SNYK-JS-COOKIE-8163060
624No Known Exploit
medium severityOpen Redirect
SNYK-JS-EXPRESS-6474509
624No Known Exploit
medium severityCross-site Scripting
SNYK-JS-EXPRESS-7926867
624No Known Exploit
medium severityRegular Expression Denial of Service (ReDoS)
SNYK-JS-PATHTOREGEXP-7925106
624Proof of Concept
medium severityRegular Expression Denial of Service (ReDoS)
SNYK-JS-PATHTOREGEXP-8482416
624Proof of Concept
medium severityServer-Side Request Forgery (SSRF)
SNYK-JS-IP-7148531
624Proof of Concept
medium severityInformation Exposure
SNYK-JS-MONGODB-5871303
624No Known Exploit
low severityCross-site Scripting
SNYK-JS-SEND-7926862
624No Known Exploit
low severityCross-site Scripting
SNYK-JS-SERVESTATIC-7926865
624No Known Exploit
Release notes
Package name: express from express GitHub release notes

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • This PR was automatically created by Snyk using the credentials of a real user.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.

Note:You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

Snyk has created this PR to upgrade express from 4.18.1 to 4.21.2.
See this package in npm:
express
See this project in Snyk:
https://app.snyk.io/org/ivancastromartinezkk/project/ace7ae74-54b8-4453-895b-bc1e87dbfbbf?utm_source=github&utm_medium=referral&page=upgrade-pr
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

@IvanCastroDev@snyk-bot