twofactor_totp icon indicating copy to clipboard operation
twofactor_totp copied to clipboard

[stable28] Fix npm audit

Open nextcloud-command opened this issue 1 year ago • 1 comments

Audit report

This audit fix resolves 27 of the total 28 vulnerabilities found in your project.

Updated dependencies

  • @chenfengyuan/vue-qrcode
  • @nextcloud/dialogs
  • @nextcloud/files
  • @nextcloud/l10n
  • @nextcloud/password-confirmation
  • @nextcloud/typings
  • @nextcloud/vue
  • @nextcloud/vue-select
  • @nextcloud/webpack-vue-config
  • @vue/component-compiler-utils
  • @vue/test-utils
  • cross-spawn
  • elliptic
  • express
  • floating-vue
  • http-proxy-middleware
  • nanoid
  • node-gettext
  • path-to-regexp
  • postcss
  • vue
  • vue-frag
  • vue-loader
  • vue-resize
  • vue-template-compiler
  • vue2-datepicker
  • vuex

Fixed vulnerabilities

@chenfengyuan/vue-qrcode #

  • Caused by vulnerable dependency:
    • vue
  • Affected versions: <=1.0.2
  • Package usage:
    • node_modules/@chenfengyuan/vue-qrcode

@nextcloud/dialogs #

  • Caused by vulnerable dependency:
    • @nextcloud/files
    • @nextcloud/l10n
    • @nextcloud/vue
    • vue
    • vue-frag
  • Affected versions: >=2.0.0
  • Package usage:
    • node_modules/@nextcloud/dialogs

@nextcloud/files #

  • Caused by vulnerable dependency:
    • @nextcloud/l10n
  • Affected versions: >=1.1.0
  • Package usage:
    • node_modules/@nextcloud/files

@nextcloud/l10n #

  • Caused by vulnerable dependency:
    • node-gettext
  • Affected versions: >=1.1.0
  • Package usage:
    • node_modules/@nextcloud/l10n

@nextcloud/password-confirmation #

  • Caused by vulnerable dependency:
    • @nextcloud/l10n
    • @nextcloud/vue
    • vue
  • Affected versions: >=3.0.0
  • Package usage:
    • node_modules/@nextcloud/password-confirmation

@nextcloud/typings #

  • Caused by vulnerable dependency:
    • vue
  • Affected versions: 1.7.0 - 1.8.0
  • Package usage:
    • node_modules/@nextcloud/typings

@nextcloud/vue #

  • Caused by vulnerable dependency:
    • @nextcloud/l10n
    • @nextcloud/vue-select
    • floating-vue
    • vue
    • vue-frag
    • vue2-datepicker
  • Affected versions: *
  • Package usage:
    • node_modules/@nextcloud/vue

@nextcloud/vue-select #

  • Caused by vulnerable dependency:
    • vue
  • Affected versions: *
  • Package usage:
    • node_modules/@nextcloud/vue-select

@nextcloud/webpack-vue-config #

  • Caused by vulnerable dependency:
    • vue
    • vue-loader
    • vue-template-compiler
  • Affected versions: *
  • Package usage:
    • node_modules/@nextcloud/webpack-vue-config

@vue/component-compiler-utils #

  • Caused by vulnerable dependency:
    • postcss
  • Affected versions: *
  • Package usage:
    • node_modules/@vue/component-compiler-utils

@vue/test-utils #

  • Caused by vulnerable dependency:
    • vue
    • vue-template-compiler
  • Affected versions: <=1.3.6
  • Package usage:
    • node_modules/@vue/test-utils

cross-spawn #

elliptic #

express #

  • Caused by vulnerable dependency:
    • path-to-regexp
  • Affected versions: 4.0.0-rc1 - 4.21.1 || 5.0.0-alpha.1 - 5.0.0-beta.3
  • Package usage:
    • node_modules/express

floating-vue #

  • Caused by vulnerable dependency:
    • vue
    • vue-resize
  • Affected versions: <=1.0.0-beta.19
  • Package usage:
    • node_modules/floating-vue

http-proxy-middleware #

nanoid #

node-gettext #

path-to-regexp #

postcss #

vue #

  • ReDoS vulnerability in vue package that is exploitable through inefficient regex evaluation in the parseHTML function
  • Severity: low (CVSS 3.7)
  • Reference: https://github.com/advisories/GHSA-5j4c-8p2g-v4jx
  • Affected versions: 2.0.0-alpha.1 - 2.7.16
  • Package usage:
    • node_modules/vue

vue-frag #

  • Caused by vulnerable dependency:
    • vue
  • Affected versions: >=1.3.1
  • Package usage:
    • node_modules/vue-frag

vue-loader #

  • Caused by vulnerable dependency:
    • @vue/component-compiler-utils
  • Affected versions: 15.0.0-beta.1 - 15.11.1
  • Package usage:
    • node_modules/vue-loader

vue-resize #

  • Caused by vulnerable dependency:
    • vue
  • Affected versions: 0.4.0 - 1.0.1
  • Package usage:
    • node_modules/vue-resize

vue-template-compiler #

vue2-datepicker #

  • Caused by vulnerable dependency:
    • vue
  • Affected versions: <=1.9.8 || 3.0.2 - 3.11.1
  • Package usage:
    • node_modules/vue2-datepicker

vuex #

  • Caused by vulnerable dependency:
    • vue
  • Affected versions: 3.1.3 - 3.6.2
  • Package usage:
    • node_modules/vuex

nextcloud-command avatar Oct 20 '24 03:10 nextcloud-command