code-push-server icon indicating copy to clipboard operation
code-push-server copied to clipboard

[Snyk] Fix for 9 vulnerabilities

Open lisong opened this issue 2 years ago • 0 comments

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

Changes included in this PR

  • Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
    • package.json
    • package-lock.json

Vulnerabilities that will be fixed

With an upgrade:
Severity Priority Score (*) Issue Breaking Change Exploit Maturity
medium severity 586/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 5.3
Regular Expression Denial of Service (ReDoS)
SNYK-JS-LODASH-1018905
No Proof of Concept
high severity 681/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.2
Command Injection
SNYK-JS-LODASH-1040724
No Proof of Concept
high severity 686/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.3
Prototype Pollution
SNYK-JS-LODASH-450202
No Proof of Concept
high severity 686/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.3
Prototype Pollution
SNYK-JS-LODASH-608086
No Proof of Concept
high severity 686/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 7.3
Prototype Pollution
SNYK-JS-LODASH-73638
No Proof of Concept
medium severity 541/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 4.4
Regular Expression Denial of Service (ReDoS)
SNYK-JS-LODASH-73639
No Proof of Concept
medium severity 646/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 6.5
Server-side Request Forgery (SSRF)
SNYK-JS-REQUEST-3361831
No Proof of Concept
medium severity 646/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 6.5
Prototype Pollution
SNYK-JS-TOUGHCOOKIE-5672873
No Proof of Concept
medium severity 636/1000
Why? Proof of Concept exploit, Has a fix available, CVSS 6.3
Prototype Pollution
npm:lodash:20180130
No Proof of Concept

(*) Note that the real score may have changed since the PR was raised.

Commit messages
Package name: aliyun-sdk The new version differs by 16 commits.
  • 3f0c2be 1.12.2
  • 6db2525 x-oss-object-acl
  • 3a3214b fix dependency
  • 17ba115 BatchCompute增加getAvailable接口
  • 06dd64d 1.12.0
  • 3c14590 Merge pull request #177 from aliyun-UED/cname_request_payer
  • c42e269 feat: support canme and requestpayer for oss
  • 3303b86 update version to 1.11.12
  • 66e03b2 Merge pull request #173 from liketic/add-new-alert-api
  • 4846276 Remove redundant required tag
  • 00b8c29 Fix method name
  • 29dc9a7 Update alert api
  • d60ce9e Merge pull request #172 from Chunlin-Li/master
  • 5d26f8b 1.11.11
  • 104d3f1 feat(APIs): 更新 SLS 中 alert 和 savedsearch 相关的 API
  • 704fcf8 update version to 1.11.10

See the full diff

Package name: cos-nodejs-sdk-v5 The new version differs by 22 commits.

See the full diff

Check the changes in this PR to ensure they won't cause issues with your project.


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report

🛠 Adjust project settings

📚 Read more about Snyk's upgrade and patch logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Regular Expression Denial of Service (ReDoS) 🦉 Prototype Pollution 🦉 Server-side Request Forgery (SSRF)

lisong avatar Nov 28 '23 14:11 lisong