Skip to content

Conversation

@nextcloud-command
Copy link
Contributor

@nextcloud-command nextcloud-command commented Feb 2, 2025

Audit report

This audit fix resolves 17 of the total 24 vulnerabilities found in your project.

Updated dependencies

Fixed vulnerabilities

@babel/helpers #

  • Babel has inefficient RegExp complexity in generated code with .replace when transpiling named capturing groups
  • Severity: moderate (CVSS 6.2)
  • Reference: GHSA-968p-4wvh-cqc8
  • Affected versions: <7.26.10
  • Package usage:
    • node_modules/@babel/helpers

@babel/runtime #

  • Babel has inefficient RegExp complexity in generated code with .replace when transpiling named capturing groups
  • Severity: moderate (CVSS 6.2)
  • Reference: GHSA-968p-4wvh-cqc8
  • Affected versions: <7.26.10
  • Package usage:
    • node_modules/@babel/runtime

@nextcloud/l10n #

  • Caused by vulnerable dependency:
  • Affected versions: 1.1.0 - 3.1.0
  • Package usage:
    • node_modules/@nextcloud/l10n

@nextcloud/webpack-vue-config #

@vue/component-compiler-utils #

  • Caused by vulnerable dependency:
  • Affected versions: *
  • Package usage:
    • node_modules/@vue/component-compiler-utils

axios #

  • axios Requests Vulnerable To Possible SSRF and Credential Leakage via Absolute URL
  • Severity: high
  • Reference: GHSA-jr5f-v2jv-69x6
  • Affected versions: 1.0.0 - 1.8.1
  • Package usage:
    • node_modules/axios

dompurify #

  • DOMPurify allows Cross-site Scripting (XSS)
  • Severity: moderate (CVSS 4.5)
  • Reference: GHSA-vhxf-7vqr-mrjg
  • Affected versions: <3.2.4
  • Package usage:
    • node_modules/dompurify

elliptic #

  • Elliptic's private key extraction in ECDSA upon signing a malformed input (e.g. a string)
  • Severity: critical 🚨
  • Reference: GHSA-vjh7-7g9h-fjfh
  • Affected versions: <=6.6.0
  • Package usage:
    • node_modules/elliptic

express #

  • Caused by vulnerable dependency:
  • Affected versions: 4.0.0-rc1 - 4.21.1 || 5.0.0-alpha.1 - 5.0.0-beta.3
  • Package usage:
    • node_modules/express

http-proxy-middleware #

  • http-proxy-middleware allows fixRequestBody to proceed even if bodyParser has failed
  • Severity: moderate (CVSS 4)
  • Reference: GHSA-9gqv-wp59-fq42
  • Affected versions: <=2.0.8
  • Package usage:
    • node_modules/http-proxy-middleware

node-gettext #

  • node-gettext vulnerable to Prototype Pollution
  • Severity: high (CVSS 5.9)
  • Reference: GHSA-g974-hxvm-x689
  • Affected versions: *
  • Package usage:
    • node_modules/node-gettext

path-to-regexp #

  • Unpatched path-to-regexp ReDoS in 0.1.x
  • Severity: high
  • Reference: GHSA-rhx6-c78j-4q9w
  • Affected versions: <0.1.12
  • Package usage:
    • node_modules/path-to-regexp

postcss #

  • PostCSS line return parsing error
  • Severity: moderate (CVSS 5.3)
  • Reference: GHSA-7fh5-64p2-3v2j
  • Affected versions: <8.4.31
  • Package usage:
    • node_modules/@vue/component-compiler-utils/node_modules/postcss

vue-loader #

  • Caused by vulnerable dependency:
  • Affected versions: 15.0.0-beta.1 - 15.11.1
  • Package usage:
    • node_modules/vue-loader

vue-resize #

  • Caused by vulnerable dependency:
  • Affected versions: 0.4.0 - 1.0.1
  • Package usage:
    • node_modules/vue-resize

vue-template-compiler #

  • vue-template-compiler vulnerable to client-side Cross-Site Scripting (XSS)
  • Severity: moderate (CVSS 4.2)
  • Reference: GHSA-g3ch-rx76-35fx
  • Affected versions: >=2.0.0
  • Package usage:
    • node_modules/vue-template-compiler

vuex #

  • Caused by vulnerable dependency:
  • Affected versions: 3.1.3 - 3.6.2
  • Package usage:
    • node_modules/vuex

@nextcloud-command nextcloud-command force-pushed the automated/noid/stable31-fix-npm-audit branch from a04dc26 to 61fb28a Compare February 9, 2025 03:16
@nextcloud-command nextcloud-command force-pushed the automated/noid/stable31-fix-npm-audit branch from 61fb28a to 32a26a5 Compare February 16, 2025 03:28
@nextcloud-command nextcloud-command force-pushed the automated/noid/stable31-fix-npm-audit branch 2 times, most recently from dacafb2 to b47e6b0 Compare March 2, 2025 03:26
@nextcloud-command nextcloud-command force-pushed the automated/noid/stable31-fix-npm-audit branch from b47e6b0 to d576baa Compare March 9, 2025 02:58
@nextcloud-command nextcloud-command force-pushed the automated/noid/stable31-fix-npm-audit branch from d576baa to 8a57e25 Compare March 16, 2025 03:23
@nextcloud-command nextcloud-command force-pushed the automated/noid/stable31-fix-npm-audit branch from 8a57e25 to a02fd47 Compare March 23, 2025 03:25
@nextcloud-command nextcloud-command force-pushed the automated/noid/stable31-fix-npm-audit branch from a02fd47 to e202311 Compare March 30, 2025 03:33
@nextcloud-command nextcloud-command force-pushed the automated/noid/stable31-fix-npm-audit branch from e202311 to 3c270ac Compare April 6, 2025 03:36
@nextcloud-command nextcloud-command force-pushed the automated/noid/stable31-fix-npm-audit branch 2 times, most recently from 87641aa to cd8eb00 Compare April 20, 2025 03:37
@nextcloud-command nextcloud-command force-pushed the automated/noid/stable31-fix-npm-audit branch from cd8eb00 to c218a2e Compare April 27, 2025 03:47
nextcloud-command and others added 2 commits April 29, 2025 10:51
@nickvergessen nickvergessen force-pushed the automated/noid/stable31-fix-npm-audit branch from d1fbf69 to c4b0fe9 Compare April 29, 2025 08:51
@DorraJaouad DorraJaouad merged commit aef2aad into stable31 Apr 29, 2025
42 checks passed
@DorraJaouad DorraJaouad deleted the automated/noid/stable31-fix-npm-audit branch April 29, 2025 10:40
@blizzz blizzz mentioned this pull request May 5, 2025
10 tasks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants