photos
photos copied to clipboard
[stable30] Fix npm audit
Audit report
This audit fix resolves 9 of the total 11 vulnerabilities found in your project.
Updated dependencies
- @vue/component-compiler-utils
- @vue/test-utils
- axios
- elliptic
- micromatch
- postcss
- vue-loader
- vue-template-compiler
- webdav
Fixed vulnerabilities
@vue/component-compiler-utils #
- Caused by vulnerable dependency:
- postcss
- Affected versions: *
- Package usage:
node_modules/@vue/component-compiler-utils
@vue/test-utils #
- Caused by vulnerable dependency:
- vue-template-compiler
- Affected versions: <=1.3.6
- Package usage:
node_modules/@vue/test-utils
axios #
- Axios Cross-Site Request Forgery Vulnerability
- Severity: moderate (CVSS 6.5)
- Reference: https://github.com/advisories/GHSA-wf5p-g6vw-rhxx
- Affected versions: 0.8.1 - 0.27.2 || 1.3.2 - 1.7.3
- Package usage:
node_modules/@nextcloud/axios/node_modules/axiosnode_modules/axiosnode_modules/wait-on/node_modules/axios
elliptic #
- Elliptic's EDDSA missing signature length check
- Severity: low (CVSS 5.3)
- Reference: https://github.com/advisories/GHSA-f7q4-pwc6-w24p
- Affected versions: 2.0.0 - 6.5.6
- Package usage:
node_modules/elliptic
micromatch #
- Regular Expression Denial of Service (ReDoS) in micromatch
- Severity: moderate
- Reference: https://github.com/advisories/GHSA-952p-6rrq-rcjv
- Affected versions: <4.0.8
- Package usage:
node_modules/micromatch
postcss #
- PostCSS line return parsing error
- Severity: moderate (CVSS 5.3)
- Reference: https://github.com/advisories/GHSA-7fh5-64p2-3v2j
- Affected versions: <8.4.31
- Package usage:
node_modules/@vue/component-compiler-utils/node_modules/postcss
vue-loader #
- Caused by vulnerable dependency:
- @vue/component-compiler-utils
- Affected versions: 15.0.0-beta.1 - 15.11.1
- Package usage:
node_modules/vue-loader
vue-template-compiler #
- vue-template-compiler vulnerable to client-side Cross-Site Scripting (XSS)
- Severity: moderate (CVSS 4.2)
- Reference: https://github.com/advisories/GHSA-g3ch-rx76-35fx
- Affected versions: >=2.0.0
- Package usage:
node_modules/vue-template-compiler
webdav #
- Caused by vulnerable dependency:
- axios
- Affected versions: 2.0.0-rc1 - 4.11.3
- Package usage:
node_modules/webdav