Skip to content

[Aqua] Fix 7 Vulnerabilities - #7

Open
aqua-security-supply-chain[bot] wants to merge 1 commit into
masterfrom
7b27910e-32c0-4550-afc4-7d7641610c0d
Open

[Aqua] Fix 7 Vulnerabilities#7
aqua-security-supply-chain[bot] wants to merge 1 commit into
masterfrom
7b27910e-32c0-4550-afc4-7d7641610c0d

Conversation

@aqua-security-supply-chain

Copy link
Copy Markdown

Aqua - Automatic PR created to fix 7 vulnerabilities

Prior to merging this PR, it's crucial to verify that the updated dependencies won't pose any issues for your application.

File Path: package.json

SeverityCVE IDPackage NameTitle
$${\color{red}CRITICAL}$$CVE-2020-7699express-fileuploadPrototype Pollution in express-fileupload
$${\color{red}CRITICAL}$$CVE-2017-1001002mathjsArbitrary Code Execution in mathjs
$${\color{red}CRITICAL}$$CVE-2017-1001003mathjsArbitrary Code Execution in mathjs
$${\color{red}CRITICAL}$$NSWG-ECO-311node-serializeCode Execution through IIFE
$${\color{orange}HIGH}$$CVE-2020-7743mathjsmathjs: prototype pollution via the deepExtend function that runs upon configuration updates
$${\color{yellow}MEDIUM}$$CVE-2020-7689bcryptInteger Overflow or Wraparound and Use of a Broken or Risky Cryptographic Algorithm in bcrypt
$${\color{green}LOW}$$GHSA-q3w9-g74q-vp5fexpress-fileuploadDenial of Service in express-fileupload

The following vulnerabilities were not fixed:

CVE IDPackage NamePathReason
CVE-2024-21508mysql2package.jsonfailed to find version 1.7.0 in file content
CVE-2024-21511mysql2package.jsonfailed to find version 1.7.0 in file content
CVE-2023-22578sequelizepackage.jsonfailed to find version 4.44.4 in file content
CVE-2023-22579sequelizepackage.jsonfailed to find version 4.44.4 in file content
CVE-2023-25813sequelizepackage.jsonfailed to find version 4.44.4 in file content
CVE-2024-21512mysql2package.jsonfailed to find version 1.7.0 in file content
CVE-2024-33883ejspackage.jsonfailed to find version 2.7.4 in file content
CVE-2024-21507mysql2package.jsonfailed to find version 1.7.0 in file content
CVE-2024-21509mysql2package.jsonfailed to find version 1.7.0 in file content
CVE-2022-25896passportpackage.jsonfailed to find version 0.4.1 in file content
CVE-2023-22580sequelizepackage.jsonfailed to find version 4.44.4 in file content

Note: if a lock file is present in the repository, it should be updated to reflect the changes made to the dependencies file.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants