server
server copied to clipboard
[master] Fix npm audit
Audit report
This audit fix resolves 23 of the total 32 vulnerabilities found in your project.
Updated dependencies
- @jimp/core
- @jimp/custom
- @nextcloud/dialogs
- @nextcloud/files
- @nextcloud/l10n
- @nextcloud/moment
- @nextcloud/password-confirmation
- @nextcloud/vue
- @testing-library/vue
- @vue/component-compiler-utils
- @vue/test-utils
- cookie
- engine.io
- nextcloud-vue-collections
- node-gettext
- node-vibrant
- path-to-regexp
- phin
- postcss
- rollup
- select2
- socket.io
- vue-loader
Fixed vulnerabilities
@jimp/core #
- Caused by vulnerable dependency:
- phin
- Affected versions: <=0.21.4--canary.1163.d07ed6254d130e2995d24101e93427ec091016e6.0
- Package usage:
node_modules/@jimp/core
@jimp/custom #
- Caused by vulnerable dependency:
- @jimp/core
- Affected versions: <=0.21.4--canary.1163.d07ed6254d130e2995d24101e93427ec091016e6.0
- Package usage:
node_modules/@jimp/custom
@nextcloud/dialogs #
- Caused by vulnerable dependency:
- @nextcloud/files
- @nextcloud/l10n
- @nextcloud/vue
- Affected versions: >=2.0.0
- Package usage:
node_modules/@nextcloud/dialogsnode_modules/@nextcloud/upload/node_modules/@nextcloud/dialogs
@nextcloud/files #
- Caused by vulnerable dependency:
- @nextcloud/l10n
- Affected versions: >=1.1.0
- Package usage:
node_modules/@nextcloud/files
@nextcloud/l10n #
- Caused by vulnerable dependency:
- node-gettext
- Affected versions: >=1.1.0
- Package usage:
node_modules/@nextcloud/l10nnode_modules/@nextcloud/moment/node_modules/@nextcloud/l10n
@nextcloud/moment #
- Caused by vulnerable dependency:
- @nextcloud/l10n
- node-gettext
- Affected versions: >=1.1.1
- Package usage:
node_modules/@nextcloud/moment
@nextcloud/password-confirmation #
- Caused by vulnerable dependency:
- @nextcloud/l10n
- @nextcloud/vue
- Affected versions: >=3.0.0
- Package usage:
node_modules/@nextcloud/password-confirmation
@nextcloud/vue #
- Caused by vulnerable dependency:
- @nextcloud/l10n
- Affected versions: >=1.4.0
- Package usage:
node_modules/@nextcloud/vue
@testing-library/vue #
- Caused by vulnerable dependency:
- @vue/test-utils
- vue-template-compiler
- Affected versions: <=5.9.0
- Package usage:
node_modules/@testing-library/vue
@vue/component-compiler-utils #
- Caused by vulnerable dependency:
- postcss
- Affected versions: *
- Package usage:
node_modules/@vue/component-compiler-utils
@vue/test-utils #
- Caused by vulnerable dependency:
- vue-template-compiler
- Affected versions: <=1.3.6
- Package usage:
node_modules/@vue/test-utils
cookie #
- cookie accepts cookie name, path, and domain with out of bounds characters
- Severity: low
- Reference: https://github.com/advisories/GHSA-pxg6-pf52-xh8x
- Affected versions: <0.7.0
- Package usage:
node_modules/cookie
engine.io #
- Caused by vulnerable dependency:
- cookie
- Affected versions: 1.8.0 - 6.6.1
- Package usage:
node_modules/engine.io
nextcloud-vue-collections #
- Caused by vulnerable dependency:
- @nextcloud/l10n
- @nextcloud/vue
- Affected versions: >=0.8.0
- Package usage:
node_modules/nextcloud-vue-collections
node-gettext #
- node-gettext vulnerable to Prototype Pollution
- Severity: moderate (CVSS 5.9)
- Reference: https://github.com/advisories/GHSA-g974-hxvm-x689
- Affected versions: *
- Package usage:
node_modules/node-gettext
node-vibrant #
- Caused by vulnerable dependency:
- @jimp/custom
- Affected versions: 3.1.5 - 3.1.6
- Package usage:
node_modules/node-vibrant
path-to-regexp #
- path-to-regexp outputs backtracking regular expressions
- Severity: high (CVSS 7.5)
- Reference: https://github.com/advisories/GHSA-9wv6-86v2-598j
- Affected versions: 0.2.0 - 1.8.0
- Package usage:
node_modules/path-to-regexp
phin #
- phin may include sensitive headers in subsequent requests after redirect
- Severity: moderate (CVSS 4.3)
- Reference: https://github.com/advisories/GHSA-x565-32qp-m3vf
- Affected versions: <3.7.1
- Package usage:
node_modules/phin
postcss #
- PostCSS line return parsing error
- Severity: moderate (CVSS 5.3)
- Reference: https://github.com/advisories/GHSA-7fh5-64p2-3v2j
- Affected versions: <8.4.31
- Package usage:
node_modules/@vue/component-compiler-utils/node_modules/postcss
rollup #
- DOM Clobbering Gadget found in rollup bundled scripts that leads to XSS
- Severity: high (CVSS 6.4)
- Reference: https://github.com/advisories/GHSA-gcx4-mw62-g8wm
- Affected versions: <2.79.2 || >=4.0.0 <4.22.4
- Package usage:
node_modules/rollupnode_modules/vite/node_modules/rollup
select2 #
- Improper Neutralization of Input During Web Page Generation in Select2
- Severity: moderate (CVSS 6.1)
- Reference: https://github.com/advisories/GHSA-rf66-hmqf-q3fc
- Affected versions: <4.0.6
- Package usage:
node_modules/select2
socket.io #
- Caused by vulnerable dependency:
- engine.io
- Affected versions: 1.6.0 - 4.7.5
- Package usage:
node_modules/socket.io
vue-loader #
- Caused by vulnerable dependency:
- @vue/component-compiler-utils
- Affected versions: 15.0.0-beta.1 - 15.11.1
- Package usage:
node_modules/vue-loader