ldap_write_support
ldap_write_support copied to clipboard
[stable29] Fix npm audit
Audit report
This audit fix resolves 8 of the total 14 vulnerabilities found in your project.
Updated dependencies
- @nextcloud/dialogs
- @nextcloud/vite-config
- @vitejs/plugin-vue2
- esbuild
- rollup-plugin-esbuild-minify
- vite
- vue
- vue-resize
Fixed vulnerabilities
@nextcloud/dialogs #
- Caused by vulnerable dependency:
- @nextcloud/vue
- vue
- vue-frag
- Affected versions: 4.2.0-beta.1 - 6.2.0
- Package usage:
node_modules/@nextcloud/dialogs
@nextcloud/vite-config #
- Caused by vulnerable dependency:
- @vitejs/plugin-vue2
- Affected versions: <=1.5.6
- Package usage:
node_modules/@nextcloud/vite-config
@vitejs/plugin-vue2 #
- Caused by vulnerable dependency:
- vue
- Affected versions: *
- Package usage:
node_modules/@vitejs/plugin-vue2
esbuild #
- esbuild enables any website to send any requests to the development server and read the response
- Severity: moderate (CVSS 5.3)
- Reference: https://github.com/advisories/GHSA-67mh-4wv8-2f99
- Affected versions: <=0.24.2
- Package usage:
node_modules/esbuildnode_modules/vite/node_modules/esbuild
rollup-plugin-esbuild-minify #
- Caused by vulnerable dependency:
- esbuild
- Affected versions: <=1.2.0
- Package usage:
node_modules/rollup-plugin-esbuild-minify
vite #
- Vite's server.fs.deny bypassed with /. for files under project root
- Severity: moderate
- Reference: https://github.com/advisories/GHSA-859w-5945-r5v3
- Affected versions: 0.11.0 - 6.1.6
- Package usage:
node_modules/vite
vue #
- ReDoS vulnerability in vue package that is exploitable through inefficient regex evaluation in the parseHTML function
- Severity: low (CVSS 3.7)
- Reference: https://github.com/advisories/GHSA-5j4c-8p2g-v4jx
- Affected versions: 2.0.0-alpha.1 - 2.7.16
- Package usage:
node_modules/vue
vue-resize #
- Caused by vulnerable dependency:
- vue
- Affected versions: 0.4.0 - 1.0.1
- Package usage:
node_modules/vue-resize