eng icon indicating copy to clipboard operation
eng copied to clipboard

security vulnerability

Open karenetheridge opened this issue 6 years ago • 0 comments

Github is sending weekly email alerts:


  | joyent / eng                                      Known security vulnerabilities detected                                                                                                                                                                                               Dependency                   tough-cookie                                                       Version                         < 2.3.3                                                                                Upgrade to                     ~> 2.3.3                                                                                   Vulnerabilities                                                                                              CVE-2017-15010                           High severity                                                                                                                           CVE-2016-1000232                           Moderate severity                                                                                                                        Defined in                                        package-lock.json | Dependency                   tough-cookie                                                       Version                         < 2.3.3                                                                                Upgrade to                     ~> 2.3.3                                                                                   Vulnerabilities                                                                                              CVE-2017-15010                           High severity                                                                                                                           CVE-2016-1000232                           Moderate severity                                                                                                                        Defined in                                        package-lock.json | Dependency                   tough-cookie                                                       Version                         < 2.3.3                                                                                Upgrade to                     ~> 2.3.3                                                                                   Vulnerabilities                                                                                              CVE-2017-15010                           High severity                                                                                                                           CVE-2016-1000232                           Moderate severity                                                                                                                        Defined in                                        package-lock.json | Dependency                   tough-cookie                                                       Version                         < 2.3.3                                                                                Upgrade to                     ~> 2.3.3                                                                                   Vulnerabilities                                                                                              CVE-2017-15010                           High severity                                                                                                                           CVE-2016-1000232                           Moderate severity                                                                                                                        Defined in                                        package-lock.json | Dependency                   tough-cookie | Version                         < 2.3.3 | Upgrade to                     ~> 2.3.3 | Vulnerabilities                                                                                              CVE-2017-15010                           High severity                                                                                                                           CVE-2016-1000232                           Moderate severity | CVE-2017-15010                           High severity | CVE-2016-1000232                           Moderate severity | Defined in                                        package-lock.json |  
-- | -- | -- | -- | -- | -- | -- | -- | -- | -- | -- | -- | --
Dependency                   tough-cookie                                                       Version                         < 2.3.3                                                                                Upgrade to                     ~> 2.3.3                                                                                   Vulnerabilities                                                                                              CVE-2017-15010                           High severity                                                                                                                           CVE-2016-1000232                           Moderate severity                                                                                                                        Defined in                                        package-lock.json | Dependency                   tough-cookie                                                       Version                         < 2.3.3                                                                                Upgrade to                     ~> 2.3.3                                                                                   Vulnerabilities                                                                                              CVE-2017-15010                           High severity                                                                                                                           CVE-2016-1000232                           Moderate severity                                                                                                                        Defined in                                        package-lock.json | Dependency                   tough-cookie                                                       Version                         < 2.3.3                                                                                Upgrade to                     ~> 2.3.3                                                                                   Vulnerabilities                                                                                              CVE-2017-15010                           High severity                                                                                                                           CVE-2016-1000232                           Moderate severity                                                                                                                        Defined in                                        package-lock.json | Dependency                   tough-cookie | Version                         < 2.3.3 | Upgrade to                     ~> 2.3.3 | Vulnerabilities                                                                                              CVE-2017-15010                           High severity                                                                                                                           CVE-2016-1000232                           Moderate severity | CVE-2017-15010                           High severity | CVE-2016-1000232                           Moderate severity | Defined in                                        package-lock.json |  
Dependency                   tough-cookie                                                       Version                         < 2.3.3                                                                                Upgrade to                     ~> 2.3.3                                                                                   Vulnerabilities                                                                                              CVE-2017-15010                           High severity                                                                                                                           CVE-2016-1000232                           Moderate severity                                                                                                                        Defined in                                        package-lock.json | Dependency                   tough-cookie                                                       Version                         < 2.3.3                                                                                Upgrade to                     ~> 2.3.3                                                                                   Vulnerabilities                                                                                              CVE-2017-15010                           High severity                                                                                                                           CVE-2016-1000232                           Moderate severity                                                                                                                        Defined in                                        package-lock.json | Dependency                   tough-cookie | Version                         < 2.3.3 | Upgrade to                     ~> 2.3.3 | Vulnerabilities                                                                                              CVE-2017-15010                           High severity                                                                                                                           CVE-2016-1000232                           Moderate severity | CVE-2017-15010                           High severity | CVE-2016-1000232                           Moderate severity | Defined in                                        package-lock.json |  
Dependency                   tough-cookie                                                       Version                         < 2.3.3                                                                                Upgrade to                     ~> 2.3.3                                                                                   Vulnerabilities                                                                                              CVE-2017-15010                           High severity                                                                                                                           CVE-2016-1000232                           Moderate severity                                                                                                                        Defined in                                        package-lock.json | Dependency                   tough-cookie | Version                         < 2.3.3 | Upgrade to                     ~> 2.3.3 | Vulnerabilities                                                                                              CVE-2017-15010                           High severity                                                                                                                           CVE-2016-1000232                           Moderate severity | CVE-2017-15010                           High severity | CVE-2016-1000232                           Moderate severity | Defined in                                        package-lock.json |  
Dependency                   tough-cookie | Version                         < 2.3.3 | Upgrade to                     ~> 2.3.3
Vulnerabilities                                                                                              CVE-2017-15010                           High severity                                                                                                                           CVE-2016-1000232                           Moderate severity | CVE-2017-15010                           High severity | CVE-2016-1000232                           Moderate severity | Defined in                                        package-lock.json |  
CVE-2017-15010                           High severity
CVE-2016-1000232                           Moderate severity

..which can also be viewed here: https://github.com/joyent/eng/network/alerts

karenetheridge avatar Jan 22 '19 20:01 karenetheridge