Skip to content

[Snyk] Fix for 23 vulnerabilities #31

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

MaxMood96
Copy link
Owner

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • coreui/package.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
high severity 696/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
Regular Expression Denial of Service (ReDoS)
SNYK-JS-ANSIREGEX-1583908
Yes Proof of Concept
critical severity 679/1000
Why? Has a fix available, CVSS 9.3
Incomplete List of Disallowed Inputs
SNYK-JS-BABELTRAVERSE-5962463
Yes No Known Exploit
high severity 696/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
Prototype Pollution
SNYK-JS-CHARTJS-1018716
Yes Proof of Concept
medium severity 479/1000
Why? Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
SNYK-JS-CSSWHAT-1298035
Yes No Known Exploit
medium severity 526/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 4.1
Arbitrary Code Injection
SNYK-JS-EJS-1049328
Yes Proof of Concept
high severity 726/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 8.1
Remote Code Execution (RCE)
SNYK-JS-EJS-2803307
Yes Proof of Concept
medium severity 586/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
SNYK-JS-GLOBPARENT-1016905
Yes Proof of Concept
medium severity 586/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
SNYK-JS-HTMLMINIFIER-3091181
Yes Proof of Concept
medium severity 479/1000
Why? Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
SNYK-JS-MINIMATCH-3050818
Yes No Known Exploit
high severity 589/1000
Why? Has a fix available, CVSS 7.5
Directory Traversal
SNYK-JS-MOMENT-2440688
Yes No Known Exploit
high severity 696/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
Regular Expression Denial of Service (ReDoS)
SNYK-JS-MOMENT-2944238
Yes Proof of Concept
medium severity 586/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 5.3
Open Redirect
SNYK-JS-NODEFORGE-2330875
Yes Proof of Concept
medium severity 529/1000
Why? Has a fix available, CVSS 6.3
Prototype Pollution
SNYK-JS-NODEFORGE-2331908
Yes No Known Exploit
medium severity 494/1000
Why? Has a fix available, CVSS 5.6
Improper Verification of Cryptographic Signature
SNYK-JS-NODEFORGE-2430337
Yes No Known Exploit
high severity 579/1000
Why? Has a fix available, CVSS 7.3
Improper Verification of Cryptographic Signature
SNYK-JS-NODEFORGE-2430339
Yes No Known Exploit
medium severity 494/1000
Why? Has a fix available, CVSS 5.6
Improper Verification of Cryptographic Signature
SNYK-JS-NODEFORGE-2430341
Yes No Known Exploit
high severity 696/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.5
Regular Expression Denial of Service (ReDoS)
SNYK-JS-NTHCHECK-1586032
Yes Proof of Concept
medium severity 479/1000
Why? Has a fix available, CVSS 5.3
Improper Input Validation
SNYK-JS-POSTCSS-5926692
Yes No Known Exploit
medium severity 646/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 6.5
Server-side Request Forgery (SSRF)
SNYK-JS-REQUEST-3361831
Yes Proof of Concept
medium severity 646/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 6.5
Prototype Pollution
SNYK-JS-TOUGHCOOKIE-5672873
Yes Proof of Concept
high severity 589/1000
Why? Has a fix available, CVSS 7.5
Denial of Service (DoS)
SNYK-JS-TRIMNEWLINES-1298042
Yes No Known Exploit
medium severity 479/1000
Why? Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
SNYK-JS-UGLIFYJS-1727251
Yes No Known Exploit
high severity 589/1000
Why? Has a fix available, CVSS 7.5
Prototype Pollution
SNYK-JS-UNSETVALUE-2400660
Yes No Known Exploit

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: @vue/cli-plugin-e2e-nightwatch The new version differs by 250 commits.
  • c913cdc v5.0.0
  • e75a288 chore: pre release sync
  • e7f07d8 docs: remove `@ next` [skip ci]
  • 80bbf38 test: skip nightwatch --parallel test for now
  • 9be19f0 test: fix tsx import
  • 5cf0e13 feat: bump default typescript version to 4.5
  • 22a4a53 chore: dependency maintenance
  • 9577cf5 chore: Merge branch 'master' into dev
  • 8b5ab22 fix: remove --skip-plugin from arguments passed to the plugins (#6972)
  • ff035c6 chore(deps): bump follow-redirects from 1.14.7 to 1.14.8 (#6993)
  • d302581 fix: update mini-css-extract-plugin to ^2.5.3 (#6987)
  • 2d8fa26 test(nightwatch): skip selenium test for now
  • 7a17d98 chore: replace eslint-plugin-graphql with @ graphl-eslint/eslint-plugin
  • 75a6d69 v5.0.0-rc.3
  • c214c3a chore: pre release sync
  • 42fc8d4 docs: add cache-loader and nightwatch breaking changes [skip ci]
  • 926855f feat!: make `cache-loader` optional (#6985)
  • 342c386 fix: there's a command response format change in nightwatch v2
  • b78a003 chore: update web drivers
  • 6c91e1a chore: update lockfile
  • 37bdc0e chore: remove the console log completely and fix lint error
  • 1c1f1ef chore: fix typo (#6964)
  • a2b6409 feat: add build stats hash support (#6980)
  • 0cbdf5f fix: specify vue version in the web component demo html

See the full diff

Package name: @vue/cli-plugin-unit-jest The new version differs by 250 commits.
  • c913cdc v5.0.0
  • e75a288 chore: pre release sync
  • e7f07d8 docs: remove `@ next` [skip ci]
  • 80bbf38 test: skip nightwatch --parallel test for now
  • 9be19f0 test: fix tsx import
  • 5cf0e13 feat: bump default typescript version to 4.5
  • 22a4a53 chore: dependency maintenance
  • 9577cf5 chore: Merge branch 'master' into dev
  • 8b5ab22 fix: remove --skip-plugin from arguments passed to the plugins (#6972)
  • ff035c6 chore(deps): bump follow-redirects from 1.14.7 to 1.14.8 (#6993)
  • d302581 fix: update mini-css-extract-plugin to ^2.5.3 (#6987)
  • 2d8fa26 test(nightwatch): skip selenium test for now
  • 7a17d98 chore: replace eslint-plugin-graphql with @ graphl-eslint/eslint-plugin
  • 75a6d69 v5.0.0-rc.3
  • c214c3a chore: pre release sync
  • 42fc8d4 docs: add cache-loader and nightwatch breaking changes [skip ci]
  • 926855f feat!: make `cache-loader` optional (#6985)
  • 342c386 fix: there's a command response format change in nightwatch v2
  • b78a003 chore: update web drivers
  • 6c91e1a chore: update lockfile
  • 37bdc0e chore: remove the console log completely and fix lint error
  • 1c1f1ef chore: fix typo (#6964)
  • a2b6409 feat: add build stats hash support (#6980)
  • 0cbdf5f fix: specify vue version in the web component demo html

See the full diff

Package name: @vue/cli-service The new version differs by 250 commits.
  • 92d80a8 v5.0.1
  • c913cdc v5.0.0
  • e75a288 chore: pre release sync
  • e7f07d8 docs: remove `@ next` [skip ci]
  • 80bbf38 test: skip nightwatch --parallel test for now
  • 9be19f0 test: fix tsx import
  • 5cf0e13 feat: bump default typescript version to 4.5
  • 22a4a53 chore: dependency maintenance
  • 9577cf5 chore: Merge branch 'master' into dev
  • 8b5ab22 fix: remove --skip-plugin from arguments passed to the plugins (#6972)
  • ff035c6 chore(deps): bump follow-redirects from 1.14.7 to 1.14.8 (#6993)
  • d302581 fix: update mini-css-extract-plugin to ^2.5.3 (#6987)
  • 2d8fa26 test(nightwatch): skip selenium test for now
  • 7a17d98 chore: replace eslint-plugin-graphql with @ graphl-eslint/eslint-plugin
  • 75a6d69 v5.0.0-rc.3
  • c214c3a chore: pre release sync
  • 42fc8d4 docs: add cache-loader and nightwatch breaking changes [skip ci]
  • 926855f feat!: make `cache-loader` optional (#6985)
  • 342c386 fix: there's a command response format change in nightwatch v2
  • b78a003 chore: update web drivers
  • 6c91e1a chore: update lockfile
  • 37bdc0e chore: remove the console log completely and fix lint error
  • 1c1f1ef chore: fix typo (#6964)
  • a2b6409 feat: add build stats hash support (#6980)

See the full diff

Package name: babel-jest The new version differs by 250 commits.
  • be16e47 v27.0.0
  • 63102ec chore: update changelog for release
  • 564694a docs(blog): Jest 27 blog post (#11131)
  • b68d91b feat(pretty-print): add option `printBasicPrototype` (#11441)
  • 2226742 chore: minor simplify format results error (#11432)
  • 78eb25d chore: remove needless assign (#11433)
  • 696c455 chore: update lockfile after publish
  • e2eb9ae v27.0.0-next.11
  • 3b253f8 Wait for closed resources to actually close before detecting open handles (#11429)
  • 27bee72 fix: run GC before collecting open handles (#11278)
  • 50451df feat: use fallback if prettier not found (#11400)
  • 150dbd8 chore: update lockfile after publish
  • 6f44529 v27.0.0-next.10
  • cbcec7d Upgrade fsevents in jest-haste-map (#11428)
  • 9633a26 feat: support reporters written in ESM (#11427)
  • 59f42d8 fix: do not cache modules that throw during evaluation (#11263)
  • 57e32e9 Detect open handles with done callbacks (#11382)
  • a397607 Document and test dontThrow for custom inline snapshot matchers (#10995)
  • 4fa3a0b feat: custom haste (#11107)
  • 2047a36 chore: bump deps (#11419)
  • a4358d6 chore: run prettier on changelog
  • bdd6282 Move all default values into `jest-config` (#9924)
  • db643a1 Link to Jest config (#11106)
  • b16082c Fix locale issue #10014 (#11412)

See the full diff

Package name: node-sass The new version differs by 90 commits.
  • 3b556c1 7.0.2
  • c716359 Bump sass-graph@^4.0.1 (#3292)
  • 24741b3 docs(readme): fix docpad plugin link
  • 1523330 feat: Drop Node 12
  • 365d357 update https://registry.npm.taobao.org to https://registry.npmmirror.com
  • 1456114 build(deps): bump actions/upload-artifact from 2 to 3
  • b465b69 chore: bump GitHub Actions to Windows 2019 (#3254)
  • e6194b1 build(deps): bump make-fetch-happen from 9.1.0 to 10.0.4
  • 4edf594 build(deps): bump node-gyp from 8.4.1 to 9.0.0
  • 29e2344 build(deps): bump actions/checkout from 2 to 3
  • 85b0d22 build(deps): bump actions/setup-node from 2 to 3
  • 3bb51da Use make-fetch-happen instead of request (#3193)
  • adc2f8b build(deps): bump true-case-path from 1.0.3 to 2.2.1 (#3000)
  • 77d12f0 chore: disable Apline for Node 16/17 builds
  • 308d533 ci: use Python 3 for Node 12
  • c818907 ci: unpin actions/setup-node to v2
  • 99242d7 7.0.1
  • 77049d1 build(deps): bump sass-graph from 2.2.5 to 4.0.0 (#3224)
  • c929f25 build(deps): bump node-gyp from 7.1.2 to 8.4.1 (#3209)
  • 918dcb3 Lint fix
  • 0a21792 Set rejectUnauthorized to true by default (#3149)
  • e80d4af chore: Drop EOL Node 15 (#3122)
  • d753397 feat: Add Node 17 support (#3195)
  • dcf2e75 build(deps-dev): bump eslint from 7.32.0 to 8.0.0

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Regular Expression Denial of Service (ReDoS)
🦉 Prototype Pollution
🦉 Arbitrary Code Injection
🦉 More lessons are available in Snyk Learn

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants