Skip to content

Restore project files#3

Open
Peterbyte wants to merge 1 commit intomtfrom
new
Open

Restore project files#3
Peterbyte wants to merge 1 commit intomtfrom
new

Conversation

@Peterbyte
Copy link
Copy Markdown
Owner

No description provided.

Repository owner deleted a comment from shinobi-dev-app bot Sep 23, 2024
@Peterbyte Peterbyte changed the title Restore project files Restore project files 1 Sep 23, 2024
@Peterbyte Peterbyte changed the title Restore project files 1 Restore project files 2 Sep 23, 2024
@Peterbyte Peterbyte changed the title Restore project files 2 Restore project files 1 Sep 23, 2024
@Peterbyte Peterbyte changed the title Restore project files 1 Restore project files 2 Sep 23, 2024
Repository owner deleted a comment from shinobi-dev-app bot Sep 23, 2024
@shinobi-dev-app
Copy link
Copy Markdown

shinobi-dev-app bot commented Sep 23, 2024

Security Review

Code Vulnerabilities:

Introduced Vulnerable Packages:

  • Critical - ejs: server-side template injection in outputFunctionName | CWE-94

    Package: ejs
    Installed Version: 2.6.2
    Fixed Version: 3.1.7
    Details

  • Critical - Mongoose Vulnerable to Prototype Pollution in Schema Object |

    Package: mongoose
    Installed Version: 5.9.6
    Fixed Version: 6.4.6, 5.13.15
    Details

  • Critical - Mongoose Prototype Pollution vulnerability | CWE-1321

    Package: mongoose
    Installed Version: 5.9.6
    Fixed Version: 7.3.3, 6.11.3, 5.13.20
    Details

  • Critical - Mongoose Vulnerable to Prototype Pollution in Schema Object |

    Package: mongoose
    Installed Version: 5.9.7
    Fixed Version: 6.4.6, 5.13.15
    Details

  • Critical - Mongoose Prototype Pollution vulnerability | CWE-1321

    Package: mongoose
    Installed Version: 5.9.7
    Fixed Version: 7.3.3, 6.11.3, 5.13.20
    Details

  • High - body-parser: Denial of Service Vulnerability in body-parser | CWE-405

    Package: body-parser
    Installed Version: 1.18.3
    Fixed Version: 1.20.3
    Details

  • High - path-to-regexp: Backtracking regular expressions cause ReDoS | CWE-1333

    Package: path-to-regexp
    Installed Version: 0.1.7
    Fixed Version: 1.9.0, 0.1.10, 8.0.0, 3.3.0, 6.3.0
    Details

  • High - express: "qs" prototype poisoning causes the hang of the node process | CWE-1321

    Package: qs
    Installed Version: 6.5.2
    Fixed Version: 6.10.3, 6.9.7, 6.8.3, 6.7.3, 6.6.1, 6.5.3, 6.4.1, 6.3.3, 6.2.4
    Details

  • High - automattic/mongoose vulnerable to Prototype pollution via Schema.path | CWE-1321

    Package: mongoose
    Installed Version: 5.9.6
    Fixed Version: 6.4.6, 5.13.15
    Details

  • High - nodejs-semver: Regular expression denial of service | CWE-1333

    Package: semver
    Installed Version: 5.7.1
    Fixed Version: 7.5.2, 6.3.1, 5.7.2
    Details

  • High - automattic/mongoose vulnerable to Prototype pollution via Schema.path | CWE-1321

    Package: mongoose
    Installed Version: 5.9.7
    Fixed Version: 6.4.6, 5.13.15
    Details

  • Medium - The ejs (aka Embedded JavaScript templates) package before 3.1.10 for ... | CWE-693

    Package: ejs
    Installed Version: 2.6.2
    Fixed Version: 3.1.10
    Details

  • Medium - express: cause malformed URLs to be evaluated | CWE-1286, CWE-601

    Package: express
    Installed Version: 4.16.4
    Fixed Version: 4.19.2, 5.0.0-beta.3
    Details

  • Medium - express: Improper Input Handling in Express Redirects | CWE-79

    Package: express
    Installed Version: 4.16.4
    Fixed Version: 4.20.0, 5.0.0
    Details

  • Medium - send: Code Execution Vulnerability in Send Library | CWE-79

    Package: send
    Installed Version: 0.16.2
    Fixed Version: 0.19.0
    Details

  • Medium - serve-static: Improper Sanitization in serve-static | CWE-79

    Package: serve-static
    Installed Version: 1.13.2
    Fixed Version: 1.16.0, 2.1.0
    Details

  • Medium - mpath: type confusion can lead to a bypass of CVE-2018-16490 | CWE-843

    Package: mpath
    Installed Version: 0.6.0
    Fixed Version: 0.8.4
    Details

  • Medium - mquery: Code injection via merge or clone operation |

    Package: mquery
    Installed Version: 3.2.2
    Fixed Version: 3.2.3
    Details

  • Medium - Spoofing attack in swagger-ui-dist | CWE-1021

    Package: swagger-ui-dist
    Installed Version: 3.25.0
    Fixed Version: 4.1.3
    Details

  • Medium - Server side request forgery in SwaggerUI |

    Package: swagger-ui-dist
    Installed Version: 3.25.0
    Fixed Version: 4.1.3
    Details

@Peterbyte Peterbyte changed the title Restore project files 2 Restore project files Sep 23, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant