| acorn |
GHSA-6chw-6frg-f759 |
HIGH |
6.1.1 |
5.7.4, 7.1.1, 6.4.1 |
Click to expand!https://github.com/acornjs/acorn/commit/793c0e569ed1158672e3a40aeed1d8518832b802 https://github.com/acornjs/acorn/issues/929 https://github.com/advisories/GHSA-6chw-6frg-f759 https://snyk.io/vuln/SNYK-JS-ACORN-559469 https://www.npmjs.com/advisories/1488
|
| ansi-html |
CVE-2021-23424 |
HIGH |
0.0.7 |
|
Click to expand!https://github.com/Tjatse/ansi-html/issues/19 https://github.com/advisories/GHSA-whgm-jr23-g3j9 https://github.com/ioet/time-tracker-ui/security/advisories/GHSA-4fjc-8q3h-8r69 https://nvd.nist.gov/vuln/detail/CVE-2021-23424 https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1567198 https://snyk.io/vuln/SNYK-JS-ANSIHTML-1296849
|
| ansi-regex |
CVE-2021-3807 |
HIGH |
3.0.0 |
5.0.1, 6.0.1 |
Click to expand!https://app.snyk.io/vuln/SNYK-JS-ANSIREGEX-1583908 https://github.com/advisories/GHSA-93q8-gq69-wqmw https://github.com/chalk/ansi-regex/commit/8d1d7cdb586269882c4bdc1b7325d0c58c8f76f9 https://github.com/chalk/ansi-regex/issues/38#issuecomment-924086311 https://github.com/chalk/ansi-regex/issues/38#issuecomment-925924774 https://huntr.dev/bounties/5b3cf33b-ede0-4398-9974-800876dfd994 https://nvd.nist.gov/vuln/detail/CVE-2021-3807
|
| browserslist |
CVE-2021-23364 |
MEDIUM |
4.4.2 |
4.16.5 |
Click to expand!https://github.com/advisories/GHSA-w8qv-6jwh-64r5 https://github.com/browserslist/browserslist/blob/e82f32d1d4100d6bc79ea0b6b6a2d281a561e33c/index.js%23L472-L474 https://github.com/browserslist/browserslist/commit/c091916910dfe0b5fd61caad96083c6709b02d98 https://github.com/browserslist/browserslist/pull/593 https://nvd.nist.gov/vuln/detail/CVE-2021-23364 https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1277182 https://snyk.io/vuln/SNYK-JS-BROWSERSLIST-1090194
|
| color-string |
CVE-2021-29060 |
MEDIUM |
1.5.3 |
1.5.5 |
Click to expand!https://github.com/Qix-/color-string/commit/0789e21284c33d89ebc4ab4ca6f759b9375ac9d3 https://github.com/Qix-/color-string/releases/tag/1.5.5 https://github.com/advisories/GHSA-257v-vj4p-3w2h https://github.com/yetingli/PoCs/blob/main/CVE-2021-29060/Color-String.md https://github.com/yetingli/SaveResults/blob/main/js/color-string.js https://nvd.nist.gov/vuln/detail/CVE-2021-29060 https://snyk.io/vuln/SNYK-JS-COLORSTRING-1082939 https://www.npmjs.com/package/color-string
|
| dns-packet |
CVE-2021-23386 |
MEDIUM |
1.3.1 |
1.3.2, 5.2.2 |
Click to expand!https://github.com/advisories/GHSA-3wcq-x3mq-6r9p https://github.com/mafintosh/dns-packet/commit/0d0d593f8df4e2712c43957a6c62e95047f12b2d https://github.com/mafintosh/dns-packet/commit/25f15dd0fedc53688b25fd053ebbdffe3d5c1c56 https://hackerone.com/bugs?subject=user&%3Breport_id=968858 https://nvd.nist.gov/vuln/detail/CVE-2021-23386 https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1295719 https://snyk.io/vuln/SNYK-JS-DNSPACKET-1293563
|
| dot-prop |
CVE-2020-8116 |
HIGH |
4.2.0 |
5.1.1, 4.2.1 |
Click to expand!https://github.com/advisories/GHSA-ff7x-qrg7-qggm https://github.com/sindresorhus/dot-prop/issues/63 https://github.com/sindresorhus/dot-prop/tree/v4 https://hackerone.com/reports/719856 https://linux.oracle.com/cve/CVE-2020-8116.html https://linux.oracle.com/errata/ELSA-2021-0548.html https://nvd.nist.gov/vuln/detail/CVE-2020-8116
|
| elliptic |
CVE-2020-13822 |
HIGH |
6.4.1 |
6.5.3 |
Click to expand!https://github.com/advisories/GHSA-vh7m-p724-62c2 https://github.com/indutny/elliptic/issues/226 https://medium.com/@herman_10687/malleability-attack-why-it-matters-7b5f59fb99a4 https://nvd.nist.gov/vuln/detail/CVE-2020-13822 https://snyk.io/vuln/SNYK-JS-ELLIPTIC-571484 https://www.npmjs.com/package/elliptic https://yondon.blog/2019/01/01/how-not-to-use-ecdsa/
|
| elliptic |
CVE-2020-28498 |
MEDIUM |
6.4.1 |
6.5.4 |
Click to expand!https://github.com/advisories/GHSA-r9p9-mrjm-926w https://github.com/christianlundkvist/blog/blob/master/2020_05_26_secp256k1_twist_attacks/secp256k1_twist_attacks.md https://github.com/indutny/elliptic/commit/441b7428b0e8f6636c42118ad2aaa186d3c34c3f https://github.com/indutny/elliptic/pull/244/commits https://nvd.nist.gov/vuln/detail/CVE-2020-28498 https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1069836 https://snyk.io/vuln/SNYK-JS-ELLIPTIC-1064899 https://www.npmjs.com/package/elliptic
|
| glob-parent |
CVE-2020-28469 |
HIGH |
3.1.0 |
5.1.2 |
Click to expand!https://github.com/advisories/GHSA-ww39-953v-wcq6 https://github.com/gulpjs/glob-parent/blob/6ce8d11f2f1ed8e80a9526b1dc8cf3aa71f43474/index.js%23L9 https://github.com/gulpjs/glob-parent/pull/36 https://github.com/gulpjs/glob-parent/releases/tag/v5.1.2 https://nvd.nist.gov/vuln/detail/CVE-2020-28469 https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBES128-1059093 https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1059092 https://snyk.io/vuln/SNYK-JS-GLOBPARENT-1016905
|
| hosted-git-info |
CVE-2021-23362 |
MEDIUM |
2.7.1 |
2.8.9, 3.0.8 |
Click to expand!https://github.com/advisories/GHSA-43f8-2h32-f4cj https://github.com/npm/hosted-git-info/commit/29adfe5ef789784c861b2cdeb15051ec2ba651a7 https://github.com/npm/hosted-git-info/commit/8d4b3697d79bcd89cdb36d1db165e3696c783a01 https://github.com/npm/hosted-git-info/commit/bede0dc38e1785e732bf0a48ba6f81a4a908eba3 https://github.com/npm/hosted-git-info/commits/v2 https://github.com/npm/hosted-git-info/pull/76 https://linux.oracle.com/cve/CVE-2021-23362.html https://linux.oracle.com/errata/ELSA-2021-3074.html https://nvd.nist.gov/vuln/detail/CVE-2021-23362 https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1088356 https://snyk.io/vuln/SNYK-JS-HOSTEDGITINFO-1088355
|
| http-proxy |
GHSA-6x33-pw7p-hmpq |
HIGH |
1.17.0 |
1.18.1 |
Click to expand!https://github.com/advisories/GHSA-6x33-pw7p-hmpq https://github.com/http-party/node-http-proxy/pull/1447/files https://www.npmjs.com/advisories/1486
|
| ini |
CVE-2020-7788 |
HIGH |
1.3.5 |
1.3.6 |
Click to expand!https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-7788 https://github.com/advisories/GHSA-qqgx-2p2h-9c37 https://github.com/npm/ini/commit/56d2805e07ccd94e2ba0984ac9240ff02d44b6f1 https://github.com/npm/ini/commit/56d2805e07ccd94e2ba0984ac9240ff02d44b6f1 (v1.3.6) https://linux.oracle.com/cve/CVE-2020-7788.html https://linux.oracle.com/errata/ELSA-2021-0551.html https://lists.debian.org/debian-lts-announce/2020/12/msg00032.html https://nvd.nist.gov/vuln/detail/CVE-2020-7788 https://snyk.io/vuln/SNYK-JS-INI-1048974 https://www.npmjs.com/advisories/1589
|
| is-svg |
CVE-2021-28092 |
HIGH |
3.0.0 |
4.2.2 |
Click to expand!https://github.com/advisories/GHSA-7r28-3m3f-r2pr https://github.com/sindresorhus/is-svg/commit/01f8a087fab8a69c3ac9085fbb16035907ab6a5b https://github.com/sindresorhus/is-svg/releases https://github.com/sindresorhus/is-svg/releases/tag/v4.2.2 https://nvd.nist.gov/vuln/detail/CVE-2021-28092 https://security.netapp.com/advisory/ntap-20210513-0008/ https://www.npmjs.com/package/is-svg
|
| js-yaml |
GHSA-8j8c-7jfh-h6hx |
HIGH |
3.12.2 |
3.13.1 |
Click to expand!https://github.com/advisories/GHSA-8j8c-7jfh-h6hx https://github.com/nodeca/js-yaml/pull/480 https://www.npmjs.com/advisories/813
|
| js-yaml |
GHSA-2pr6-76vf-7546 |
MEDIUM |
3.12.2 |
3.13.0 |
Click to expand!https://github.com/advisories/GHSA-2pr6-76vf-7546 https://github.com/nodeca/js-yaml/commit/a567ef3c6e61eb319f0bfc2671d91061afb01235 https://github.com/nodeca/js-yaml/issues/475 https://snyk.io/vuln/SNYK-JS-JSYAML-173999 https://www.npmjs.com/advisories/788 https://www.npmjs.com/advisories/788/versions
|
| kind-of |
CVE-2019-20149 |
HIGH |
6.0.2 |
6.0.3 |
Click to expand!https://github.com/advisories/GHSA-6c8f-qphg-qjgp https://github.com/jonschlinkert/kind-of/commit/1df992ce6d5a1292048e5fe9c52c5382f941ee0b https://github.com/jonschlinkert/kind-of/issues/30 https://github.com/jonschlinkert/kind-of/pull/31 https://nvd.nist.gov/vuln/detail/CVE-2019-20149 https://snyk.io/vuln/SNYK-JS-KINDOF-537849 https://www.npmjs.com/advisories/1490
|
| lodash |
CVE-2019-10744 |
CRITICAL |
4.17.11 |
4.17.12 |
Click to expand!https://access.redhat.com/errata/RHSA-2019:3024 https://github.com/advisories/GHSA-jf85-cpcp-j695 https://github.com/lodash/lodash/pull/4336 https://nvd.nist.gov/vuln/detail/CVE-2019-10744 https://security.netapp.com/advisory/ntap-20191004-0005/ https://snyk.io/vuln/SNYK-JS-LODASH-450202 https://support.f5.com/csp/article/K47105354?utm_source=f5support&utm_medium=RSS https://www.npmjs.com/advisories/1065 https://www.oracle.com/security-alerts/cpujan2021.html https://www.oracle.com/security-alerts/cpuoct2020.html
|
| lodash |
CVE-2020-8203 |
HIGH |
4.17.11 |
4.17.19 |
Click to expand!https://github.com/advisories/GHSA-p6mc-m468-83gw https://github.com/lodash/lodash/commit/c84fe82760fb2d3e03a63379b297a1cc1a2fce12 https://github.com/lodash/lodash/issues/4744 https://github.com/lodash/lodash/issues/4874 https://hackerone.com/reports/712065 https://nvd.nist.gov/vuln/detail/CVE-2020-8203 https://security.netapp.com/advisory/ntap-20200724-0006/ https://www.npmjs.com/advisories/1523 https://www.oracle.com//security-alerts/cpujul2021.html https://www.oracle.com/security-alerts/cpuApr2021.html https://www.oracle.com/security-alerts/cpuoct2021.html
|
| lodash |
CVE-2021-23337 |
HIGH |
4.17.11 |
4.17.21 |
Click to expand!https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-23337 https://github.com/advisories/GHSA-35jh-r3h4-6jhm https://github.com/lodash/lodash/blob/ddfd9b11a0126db2302cb70ec9973b66baec0975/lodash.js#L14851 https://github.com/lodash/lodash/blob/ddfd9b11a0126db2302cb70ec9973b66baec0975/lodash.js%23L14851 https://github.com/lodash/lodash/commit/3469357cff396a26c363f8c1b5a91dde28ba4b1c https://nvd.nist.gov/vuln/detail/CVE-2021-23337 https://security.netapp.com/advisory/ntap-20210312-0006/ https://snyk.io/vuln/SNYK-JAVA-ORGFUJIONWEBJARS-1074932 https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARS-1074930 https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-1074928 https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBLODASH-1074931 https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1074929 https://snyk.io/vuln/SNYK-JS-LODASH-1040724 https://www.oracle.com//security-alerts/cpujul2021.html https://www.oracle.com/security-alerts/cpuoct2021.html
|
| mem |
GHSA-4xcv-9jjx-gfj3 |
MEDIUM |
1.1.0 |
4.0.0 |
Click to expand!https://bugzilla.redhat.com/show_bug.cgi?id=1623744 https://github.com/advisories/GHSA-4xcv-9jjx-gfj3 https://github.com/sindresorhus/mem/commit/da4e4398cb27b602de3bd55f746efa9b4a31702b https://snyk.io/vuln/npm:mem:20180117 https://www.npmjs.com/advisories/1084
|
| minimist |
CVE-2020-7598 |
MEDIUM |
0.0.8 |
1.2.3, 0.2.1 |
Click to expand!http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00024.html https://github.com/advisories/GHSA-vh95-rmgr-6w4m https://github.com/substack/minimist/commit/38a4d1caead72ef99e824bb420a2528eec03d9ab https://github.com/substack/minimist/commit/4cf1354839cb972e38496d35e12f806eea92c11f#diff-a1e0ee62c91705696ddb71aa30ad4f95 https://github.com/substack/minimist/commit/63e7ed05aa4b1889ec2f3b196426db4500cbda94 https://linux.oracle.com/cve/CVE-2020-7598.html https://linux.oracle.com/errata/ELSA-2020-2852.html https://nvd.nist.gov/vuln/detail/CVE-2020-7598 https://snyk.io/vuln/SNYK-JS-MINIMIST-559764 https://www.npmjs.com/advisories/1179
|
| minimist |
CVE-2020-7598 |
MEDIUM |
1.2.0 |
1.2.3, 0.2.1 |
Click to expand!http://lists.opensuse.org/opensuse-security-announce/2020-06/msg00024.html https://github.com/advisories/GHSA-vh95-rmgr-6w4m https://github.com/substack/minimist/commit/38a4d1caead72ef99e824bb420a2528eec03d9ab https://github.com/substack/minimist/commit/4cf1354839cb972e38496d35e12f806eea92c11f#diff-a1e0ee62c91705696ddb71aa30ad4f95 https://github.com/substack/minimist/commit/63e7ed05aa4b1889ec2f3b196426db4500cbda94 https://linux.oracle.com/cve/CVE-2020-7598.html https://linux.oracle.com/errata/ELSA-2020-2852.html https://nvd.nist.gov/vuln/detail/CVE-2020-7598 https://snyk.io/vuln/SNYK-JS-MINIMIST-559764 https://www.npmjs.com/advisories/1179
|
| mixin-deep |
CVE-2019-10746 |
CRITICAL |
1.3.1 |
2.0.1, 1.3.2 |
Click to expand!https://github.com/advisories/GHSA-fhjf-83wg-r2j9 https://linux.oracle.com/cve/CVE-2019-10746.html https://linux.oracle.com/errata/ELSA-2021-0549.html https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BFNIVG2XYFPZJY3DYYBJASZ7ZMKBMIJT/ https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UXRA365KZCUNXMU3KDH5JN5BEPNIGUKC/ https://nvd.nist.gov/vuln/detail/CVE-2019-10746 https://snyk.io/vuln/SNYK-JS-MIXINDEEP-450212 https://www.npmjs.com/advisories/1013
|
| node-forge |
CVE-2020-7720 |
HIGH |
0.7.5 |
0.10.0 |
Click to expand!https://github.com/advisories/GHSA-92xj-mqp7-vmcj https://github.com/digitalbazaar/forge/blob/master/CHANGELOG.md https://github.com/digitalbazaar/forge/blob/master/CHANGELOG.md#removed https://nvd.nist.gov/vuln/detail/CVE-2020-7720 https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-609293 https://snyk.io/vuln/SNYK-JS-NODEFORGE-598677
|
| node-notifier |
CVE-2020-7789 |
MEDIUM |
5.4.0 |
8.0.1 |
Click to expand!https://github.com/advisories/GHSA-5fw9-fq32-wv5p https://github.com/mikaelbr/node-notifier/blob/master/lib/utils.js%23L303 https://github.com/mikaelbr/node-notifier/commit/5d62799dab88505a709cd032653b2320c5813fce https://nvd.nist.gov/vuln/detail/CVE-2020-7789 https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1050371 https://snyk.io/vuln/SNYK-JS-NODENOTIFIER-1035794
|
| nth-check |
CVE-2021-3803 |
HIGH |
1.0.2 |
2.0.1 |
Click to expand!https://github.com/advisories/GHSA-rp65-9cf3-cjxr https://github.com/fb55/nth-check/commit/9894c1d2010870c351f66c6f6efcf656e26bb726 https://huntr.dev/bounties/8cf8cc06-d2cf-4b4e-b42c-99fafb0b04d0 https://nvd.nist.gov/vuln/detail/CVE-2021-3803
|
| object-path |
CVE-2020-15256 |
CRITICAL |
0.9.2 |
0.11.5 |
Click to expand!https://github.com/advisories/GHSA-cwx2-736x-mf6w https://github.com/mariocasciaro/object-path/commit/2be3354c6c46215c7635eb1b76d80f1319403c68 https://github.com/mariocasciaro/object-path/security/advisories/GHSA-cwx2-736x-mf6w https://nvd.nist.gov/vuln/detail/CVE-2020-15256
|
| object-path |
CVE-2021-23434 |
HIGH |
0.9.2 |
0.11.6 |
Click to expand!https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-23434 https://github.com/advisories/GHSA-v39p-96qg-c8rf https://github.com/mariocasciaro/object-path#0116 https://github.com/mariocasciaro/object-path%230116 https://github.com/mariocasciaro/object-path/commit/7bdf4abefd102d16c163d633e8994ef154cab9eb https://nvd.nist.gov/vuln/detail/CVE-2021-23434 https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1570423 https://snyk.io/vuln/SNYK-JS-OBJECTPATH-1569453
|
| object-path |
CVE-2021-3805 |
HIGH |
0.9.2 |
0.11.8 |
Click to expand!https://github.com/advisories/GHSA-8v63-cqqc-6r2c https://github.com/mariocasciaro/object-path/commit/e6bb638ffdd431176701b3e9024f80050d0ef0a6 https://huntr.dev/bounties/571e3baf-7c46-46e3-9003-ba7e4e623053 https://nvd.nist.gov/vuln/detail/CVE-2021-3805
|
| path-parse |
CVE-2021-23343 |
HIGH |
1.0.6 |
1.0.7 |
Click to expand!https://github.com/advisories/GHSA-hj48-42vr-x3v9 https://github.com/jbgutierrez/path-parse/commit/eca63a7b9a473bf6978a2f5b7b3343662d1506f7 https://github.com/jbgutierrez/path-parse/issues/8 https://github.com/jbgutierrez/path-parse/pull/10 https://linux.oracle.com/cve/CVE-2021-23343.html https://linux.oracle.com/errata/ELSA-2021-3666.html https://lists.apache.org/thread.html/r6a32cb3eda3b19096ad48ef1e7aa8f26e005f2f63765abb69ce08b85@%3Cdev.myfaces.apache.org%3E https://nvd.nist.gov/vuln/detail/CVE-2021-23343 https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1279028 https://snyk.io/vuln/SNYK-JS-PATHPARSE-1077067
|
| postcss |
CVE-2021-23368 |
MEDIUM |
7.0.14 |
8.2.10, 7.0.36 |
Click to expand!https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-23368 https://github.com/advisories/GHSA-hwj9-h5mp-3pm3 https://github.com/postcss/postcss/commit/54cbf3c4847eb0fb1501b9d2337465439e849734 https://github.com/postcss/postcss/commit/8682b1e4e328432ba692bed52326e84439cec9e4 https://github.com/postcss/postcss/commit/b6f3e4d5a8d7504d553267f80384373af3a3dec5 https://lists.apache.org/thread.html/r00158f5d770d75d0655c5eef1bdbc6150531606c8f8bcb778f0627be@%3Cdev.myfaces.apache.org%3E https://lists.apache.org/thread.html/r16e295b4f02d81b79981237d602cb0b9e59709bafaa73ac98be7cef1@%3Cdev.myfaces.apache.org%3E https://lists.apache.org/thread.html/r49afb49b38748897211b1f89c3a64dc27f9049474322b05715695aab@%3Cdev.myfaces.apache.org%3E https://lists.apache.org/thread.html/r5acd89f3827ad9a9cad6d24ed93e377f7114867cd98cfba616c6e013@%3Ccommits.myfaces.apache.org%3E https://lists.apache.org/thread.html/r8def971a66cf3e375178fbee752e1b04a812a047cc478ad292007e33@%3Cdev.myfaces.apache.org%3E https://lists.apache.org/thread.html/rad5af2044afb51668b1008b389ac815a28ecea9eb75ae2cab5a00ebb@%3Ccommits.myfaces.apache.org%3E https://nvd.nist.gov/vuln/detail/CVE-2021-23368 https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1244795 https://snyk.io/vuln/SNYK-JS-POSTCSS-1090595
|
| serialize-javascript |
CVE-2020-7660 |
HIGH |
1.6.1 |
3.1.0 |
Click to expand!https://github.com/advisories/GHSA-hxcc-f52p-wc94 https://github.com/yahoo/serialize-javascript/commit/f21a6fb3ace2353413761e79717b2d210ba6ccbd https://nvd.nist.gov/vuln/detail/CVE-2020-7660
|
| serialize-javascript |
CVE-2019-16769 |
MEDIUM |
1.6.1 |
2.1.1 |
Click to expand!https://github.com/advisories/GHSA-h9rv-jmmf-4pgx https://github.com/yahoo/serialize-javascript/security/advisories/GHSA-h9rv-jmmf-4pgx https://nvd.nist.gov/vuln/detail/CVE-2019-16769 https://www.npmjs.com/advisories/1426
|
| set-value |
CVE-2019-10747 |
CRITICAL |
0.4.3 |
3.0.1, 2.0.1 |
Click to expand!https://github.com/advisories/GHSA-4g88-fppr-53pp https://linux.oracle.com/cve/CVE-2019-10747.html https://linux.oracle.com/errata/ELSA-2021-0549.html https://lists.apache.org/thread.html/b46f35559c4a97cf74d2dd7fe5a48f8abf2ff37f879083920af9b292@%3Cdev.drat.apache.org%3E https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3EJ36KV6MXQPUYTFCCTDY54E5Y7QP3AV/ https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/E3HNLQZQINMZK6GYB2UTKK4VU7WBV2OT/ https://nvd.nist.gov/vuln/detail/CVE-2019-10747 https://snyk.io/vuln/SNYK-JS-SETVALUE-450213 https://www.npmjs.com/advisories/1012
|
| set-value |
CVE-2021-23440 |
CRITICAL |
0.4.3 |
2.0.1, 4.0.1 |
Click to expand!https://github.com/advisories/GHSA-4jqc-8m5r-9rpr https://github.com/jonschlinkert/set-value/commit/7cf8073bb06bf0c15e08475f9f952823b4576452 https://github.com/jonschlinkert/set-value/pull/33 https://nvd.nist.gov/vuln/detail/CVE-2021-23440 https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1584212 https://snyk.io/vuln/SNYK-JS-SETVALUE-1540541 https://www.huntr.dev/bounties/2eae1159-01de-4f82-a177-7478a408c4a2/
|
| set-value |
CVE-2019-10747 |
CRITICAL |
2.0.0 |
3.0.1, 2.0.1 |
Click to expand!https://github.com/advisories/GHSA-4g88-fppr-53pp https://linux.oracle.com/cve/CVE-2019-10747.html https://linux.oracle.com/errata/ELSA-2021-0549.html https://lists.apache.org/thread.html/b46f35559c4a97cf74d2dd7fe5a48f8abf2ff37f879083920af9b292@%3Cdev.drat.apache.org%3E https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3EJ36KV6MXQPUYTFCCTDY54E5Y7QP3AV/ https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/E3HNLQZQINMZK6GYB2UTKK4VU7WBV2OT/ https://nvd.nist.gov/vuln/detail/CVE-2019-10747 https://snyk.io/vuln/SNYK-JS-SETVALUE-450213 https://www.npmjs.com/advisories/1012
|
| set-value |
CVE-2021-23440 |
CRITICAL |
2.0.0 |
2.0.1, 4.0.1 |
Click to expand!https://github.com/advisories/GHSA-4jqc-8m5r-9rpr https://github.com/jonschlinkert/set-value/commit/7cf8073bb06bf0c15e08475f9f952823b4576452 https://github.com/jonschlinkert/set-value/pull/33 https://nvd.nist.gov/vuln/detail/CVE-2021-23440 https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1584212 https://snyk.io/vuln/SNYK-JS-SETVALUE-1540541 https://www.huntr.dev/bounties/2eae1159-01de-4f82-a177-7478a408c4a2/
|
| sockjs |
CVE-2020-7693 |
MEDIUM |
0.3.19 |
0.3.20 |
Click to expand!https://github.com/advisories/GHSA-c9g6-9335-x697 https://github.com/andsnw/sockjs-dos-py https://github.com/sockjs/sockjs-node/commit/dd7e642cd69ee74385825816d30642c43e051d16 https://github.com/sockjs/sockjs-node/issues/252 https://github.com/sockjs/sockjs-node/pull/265 https://nvd.nist.gov/vuln/detail/CVE-2020-7693 https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-575448 https://snyk.io/vuln/SNYK-JS-SOCKJS-575261 https://www.npmjs.com/package/sockjs
|
| ssri |
CVE-2021-27290 |
HIGH |
6.0.1 |
8.0.1, 7.1.1, 6.0.2 |
Click to expand!https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-27290 https://doyensec.com/resources/Doyensec_Advisory_ssri_redos.pdf https://github.com/advisories/GHSA-vx3p-948g-6vhq https://github.com/npm/ssri/commit/76e223317d971f19e4db8191865bdad5edee40d2 https://github.com/npm/ssri/commit/b30dfdb00bb94ddc49a25a85a18fb27afafdfbb1 https://github.com/npm/ssri/pull/20#issuecomment-842677644 https://github.com/yetingli/SaveResults/blob/main/pdf/ssri-redos.pdf https://linux.oracle.com/cve/CVE-2021-27290.html https://linux.oracle.com/errata/ELSA-2021-3074.html https://npmjs.com https://nvd.nist.gov/vuln/detail/CVE-2021-27290 https://www.npmjs.com/package/ssri https://www.oracle.com/security-alerts/cpuoct2021.html
|
| tar |
CVE-2021-32803 |
HIGH |
4.4.8 |
6.1.2, 5.0.7, 4.4.15, 3.2.3 |
Click to expand!https://github.com/advisories/GHSA-r628-mhmh-qjhw https://github.com/npm/node-tar/commit/9dbdeb6df8e9dbd96fa9e84341b9d74734be6c20 https://github.com/npm/node-tar/security/advisories/GHSA-r628-mhmh-qjhw https://linux.oracle.com/cve/CVE-2021-32803.html https://linux.oracle.com/errata/ELSA-2021-3666.html https://nvd.nist.gov/vuln/detail/CVE-2021-32803 https://www.npmjs.com/advisories/1771 https://www.npmjs.com/package/tar https://www.oracle.com/security-alerts/cpuoct2021.html
|
| tar |
CVE-2021-32804 |
HIGH |
4.4.8 |
6.1.1, 5.0.6, 4.4.14, 3.2.2 |
Click to expand!https://github.com/advisories/GHSA-3jfq-g458-7qm9 https://github.com/npm/node-tar/commit/1f036ca23f64a547bdd6c79c1a44bc62e8115da4 https://github.com/npm/node-tar/security/advisories/GHSA-3jfq-g458-7qm9 https://linux.oracle.com/cve/CVE-2021-32804.html https://linux.oracle.com/errata/ELSA-2021-3666.html https://nvd.nist.gov/vuln/detail/CVE-2021-32804 https://www.npmjs.com/advisories/1770 https://www.npmjs.com/package/tar https://www.oracle.com/security-alerts/cpuoct2021.html
|
| tar |
CVE-2021-37701 |
HIGH |
4.4.8 |
6.1.7, 5.0.8, 4.4.16 |
Click to expand!https://github.com/advisories/GHSA-9r2w-394v-53qc https://github.com/npm/node-tar/security/advisories/GHSA-9r2w-394v-53qc https://nvd.nist.gov/vuln/detail/CVE-2021-37701 https://www.debian.org/security/2021/dsa-5008 https://www.npmjs.com/advisories/1779 https://www.npmjs.com/package/tar https://www.oracle.com/security-alerts/cpuoct2021.html
|
| tar |
CVE-2021-37712 |
HIGH |
4.4.8 |
6.1.9, 5.0.10, 4.4.18 |
Click to expand!https://github.com/advisories/GHSA-qq89-hq3f-393p https://github.com/npm/node-tar/security/advisories/GHSA-qq89-hq3f-393p https://nvd.nist.gov/vuln/detail/CVE-2021-37712 https://www.debian.org/security/2021/dsa-5008 https://www.npmjs.com/advisories/1780 https://www.npmjs.com/package/tar https://www.oracle.com/security-alerts/cpuoct2021.html
|
| tar |
CVE-2021-37713 |
HIGH |
4.4.8 |
6.1.9, 5.0.10, 4.4.18 |
Click to expand!https://github.com/advisories/GHSA-5955-9wpr-37jh https://github.com/npm/node-tar/security/advisories/GHSA-5955-9wpr-37jh https://nvd.nist.gov/vuln/detail/CVE-2021-37713 https://www.npmjs.com/package/tar https://www.oracle.com/security-alerts/cpuoct2021.html
|
| url-parse |
CVE-2021-27515 |
MEDIUM |
1.4.4 |
1.5.0 |
Click to expand!https://advisory.checkmarx.net/advisory/CX-2021-4306 https://github.com/advisories/GHSA-9m6j-fcg5-2442 https://github.com/unshiftio/url-parse/commit/d1e7e8822f26e8a49794b757123b51386325b2b0 https://github.com/unshiftio/url-parse/compare/1.4.7...1.5.0 https://github.com/unshiftio/url-parse/pull/197 https://nvd.nist.gov/vuln/detail/CVE-2021-27515
|
| url-parse |
CVE-2021-3664 |
MEDIUM |
1.4.4 |
1.5.2 |
Click to expand!https://github.com/advisories/GHSA-hh27-ffr2-f2jc https://github.com/unshiftio/url-parse/commit/81ab967889b08112d3356e451bf03e6aa0cbb7e0 https://github.com/unshiftio/url-parse/issues/205 https://github.com/unshiftio/url-parse/issues/206 https://huntr.dev/bounties/1625557993985-unshiftio/url-parse https://huntr.dev/bounties/1625557993985-unshiftio/url-parse/ https://nvd.nist.gov/vuln/detail/CVE-2021-3664
|
| websocket-extensions |
CVE-2020-7662 |
HIGH |
0.1.3 |
0.1.4 |
Click to expand!https://blog.jcoglan.com/2020/06/02/redos-vulnerability-in-websocket-extensions https://github.com/advisories/GHSA-g78m-2chm-r7qv https://github.com/faye/websocket-extensions-node/commit/29496f6838bfadfe5a2f85dff33ed0ba33873237 https://github.com/faye/websocket-extensions-node/security/advisories/GHSA-g78m-2chm-r7qv https://nvd.nist.gov/vuln/detail/CVE-2020-7662 https://snyk.io/vuln/SNYK-JS-WEBSOCKETEXTENSIONS-570623
|
| y18n |
CVE-2020-7774 |
HIGH |
3.2.1 |
5.0.5, 4.0.1, 3.2.2 |
Click to expand!https://github.com/advisories/GHSA-c4w7-xm78-47vh https://github.com/yargs/y18n/commit/a9ac604abf756dec9687be3843e2c93bfe581f25 https://github.com/yargs/y18n/issues/96 https://github.com/yargs/y18n/pull/108 https://linux.oracle.com/cve/CVE-2020-7774.html https://linux.oracle.com/errata/ELSA-2021-0551.html https://nvd.nist.gov/vuln/detail/CVE-2020-7774 https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1038306 https://snyk.io/vuln/SNYK-JS-Y18N-1021887 https://www.oracle.com/security-alerts/cpuApr2021.html
|
| y18n |
CVE-2020-7774 |
HIGH |
4.0.0 |
5.0.5, 4.0.1, 3.2.2 |
Click to expand!https://github.com/advisories/GHSA-c4w7-xm78-47vh https://github.com/yargs/y18n/commit/a9ac604abf756dec9687be3843e2c93bfe581f25 https://github.com/yargs/y18n/issues/96 https://github.com/yargs/y18n/pull/108 https://linux.oracle.com/cve/CVE-2020-7774.html https://linux.oracle.com/errata/ELSA-2021-0551.html https://nvd.nist.gov/vuln/detail/CVE-2020-7774 https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1038306 https://snyk.io/vuln/SNYK-JS-Y18N-1021887 https://www.oracle.com/security-alerts/cpuApr2021.html
|
| yargs-parser |
CVE-2020-7608 |
MEDIUM |
10.1.0 |
5.0.1, 13.1.2, 18.1.2, 15.0.1 |
Click to expand!https://github.com/advisories/GHSA-p9pc-299p-vxgp https://github.com/yargs/yargs-parser/commit/63810ca1ae1a24b08293a4d971e70e058c7a41e2 https://linux.oracle.com/cve/CVE-2020-7608.html https://linux.oracle.com/errata/ELSA-2021-0548.html https://nvd.nist.gov/vuln/detail/CVE-2020-7608 https://snyk.io/vuln/SNYK-JS-YARGSPARSER-560381 https://www.npmjs.com/advisories/1500
|
| yargs-parser |
CVE-2020-7608 |
MEDIUM |
11.1.1 |
5.0.1, 13.1.2, 18.1.2, 15.0.1 |
Click to expand!https://github.com/advisories/GHSA-p9pc-299p-vxgp https://github.com/yargs/yargs-parser/commit/63810ca1ae1a24b08293a4d971e70e058c7a41e2 https://linux.oracle.com/cve/CVE-2020-7608.html https://linux.oracle.com/errata/ELSA-2021-0548.html https://nvd.nist.gov/vuln/detail/CVE-2020-7608 https://snyk.io/vuln/SNYK-JS-YARGSPARSER-560381 https://www.npmjs.com/advisories/1500
|
| yargs-parser |
CVE-2020-7608 |
MEDIUM |
7.0.0 |
5.0.1, 13.1.2, 18.1.2, 15.0.1 |
Click to expand!https://github.com/advisories/GHSA-p9pc-299p-vxgp https://github.com/yargs/yargs-parser/commit/63810ca1ae1a24b08293a4d971e70e058c7a41e2 https://linux.oracle.com/cve/CVE-2020-7608.html https://linux.oracle.com/errata/ELSA-2021-0548.html https://nvd.nist.gov/vuln/detail/CVE-2020-7608 https://snyk.io/vuln/SNYK-JS-YARGSPARSER-560381 https://www.npmjs.com/advisories/1500
|
| composer |
|
|
|
|
|