Skip to content

Conversation

tom-reinders
Copy link

No description provided.

@vulnerability-report
Copy link

🤖 Vulnerability Report

  • Critical: 2 vulnerabilities
  • High: 11 vulnerabilities
  • Low: 1 vulnerabilities
  • Moderate: 7 vulnerabilities
View details
  • (critical) [npm] lodash - Prototype Pollution in lodash
  • (critical) [npm] minimist - Prototype Pollution in minimist
  • (high) [npm] tough-cookie - Regular Expression Denial of Service in tough-cookie
  • (high) [npm] lodash - Prototype Pollution in lodash
  • (high) [npm] elliptic - Signature Malleabillity in elliptic
  • (high) [npm] lodash - Command Injection in lodash
  • (high) [npm] ssh2 - OS Command Injection in ssh2
  • (high) [npm] follow-redirects - Exposure of sensitive information in follow-redirects
  • (high) [npm] node-fetch - node-fetch is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
  • (high) [npm] lodash - Prototype Pollution in lodash
  • (high) [npm] axios - axios Inefficient Regular Expression Complexity vulnerability
  • (high) [npm] moment - Path Traversal: 'dir/../../filename' in moment.locale
  • (high) [npm] moment - Moment.js vulnerable to Inefficient Regular Expression Complexity
  • (moderate) [npm] tough-cookie - ReDoS via long string of semicolons in tough-cookie
  • (moderate) [npm] lodash - Regular Expression Denial of Service (ReDoS) in lodash
  • (moderate) [npm] base64url - Out-of-bounds Read in base64url
  • (moderate) [npm] elliptic - Use of a Broken or Risky Cryptographic Algorithm
  • (moderate) [npm] lodash - Regular Expression Denial of Service (ReDoS) in lodash
  • (moderate) [npm] follow-redirects - Exposure of Sensitive Information to an Unauthorized Actor in follow-redirects
  • (moderate) [npm] @actions/core - @actions/core has Delimiter Injection Vulnerability in exportVariable
  • (low) [npm] lodash - Prototype Pollution in lodash

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant