richdocuments
richdocuments copied to clipboard
[stable31] Fix npm audit
Audit report
This audit fix resolves 10 of the total 17 vulnerabilities found in your project.
Updated dependencies
- @nextcloud/dialogs
- @nextcloud/webpack-vue-config
- @vue/component-compiler-utils
- brace-expansion
- postcss
- tar-fs
- vue-loader
- vue-resize
- vue-template-compiler
- webpack-dev-server
Fixed vulnerabilities
@nextcloud/dialogs #
- Caused by vulnerable dependency:
- @nextcloud/vue
- vue
- vue-frag
- Affected versions: 4.2.0-beta.1 - 6.3.1
- Package usage:
node_modules/@nextcloud/dialogs
@nextcloud/webpack-vue-config #
- Caused by vulnerable dependency:
- vue
- vue-loader
- vue-template-compiler
- Affected versions: <=6.2.0
- Package usage:
node_modules/@nextcloud/webpack-vue-config
@vue/component-compiler-utils #
- Caused by vulnerable dependency:
- postcss
- Affected versions: *
- Package usage:
node_modules/@vue/component-compiler-utils
brace-expansion #
- brace-expansion Regular Expression Denial of Service vulnerability
- Severity: low (CVSS 3.1)
- Reference: https://github.com/advisories/GHSA-v6h2-p8h4-qcjw
- Affected versions: 1.0.0 - 1.1.11 || 2.0.0 - 2.0.1
- Package usage:
node_modules/@typescript-eslint/typescript-estree/node_modules/brace-expansionnode_modules/brace-expansionnode_modules/detective-typescript/node_modules/brace-expansionnode_modules/webdav/node_modules/brace-expansion
postcss #
- PostCSS line return parsing error
- Severity: moderate (CVSS 5.3)
- Reference: https://github.com/advisories/GHSA-7fh5-64p2-3v2j
- Affected versions: <8.4.31
- Package usage:
node_modules/@vue/component-compiler-utils/node_modules/postcss
tar-fs #
- tar-fs can extract outside the specified dir with a specific tarball
- Severity: high
- Reference: https://github.com/advisories/GHSA-8cj5-5rvv-wf4v
- Affected versions: 2.0.0 - 2.1.2
- Package usage:
node_modules/tar-fs
vue-loader #
- Caused by vulnerable dependency:
- @vue/component-compiler-utils
- Affected versions: 15.0.0-beta.1 - 15.11.1
- Package usage:
node_modules/vue-loader
vue-resize #
- Caused by vulnerable dependency:
- vue
- Affected versions: 0.4.0 - 1.0.1
- Package usage:
node_modules/vue-resize
vue-template-compiler #
- vue-template-compiler vulnerable to client-side Cross-Site Scripting (XSS)
- Severity: moderate (CVSS 4.2)
- Reference: https://github.com/advisories/GHSA-g3ch-rx76-35fx
- Affected versions: >=2.0.0
- Package usage:
node_modules/vue-template-compiler
webpack-dev-server #
- webpack-dev-server users' source code may be stolen when they access a malicious web site with non-Chromium based browser
- Severity: moderate (CVSS 6.5)
- Reference: https://github.com/advisories/GHSA-9jgg-88mc-972h
- Affected versions: <=5.2.0
- Package usage:
node_modules/webpack-dev-server