twofactor_totp
                                
                                 twofactor_totp copied to clipboard
                                
                                    twofactor_totp copied to clipboard
                            
                            
                            
                        [stable28] Fix npm audit
Audit report
This audit fix resolves 27 of the total 28 vulnerabilities found in your project.
Updated dependencies
- @chenfengyuan/vue-qrcode
- @nextcloud/dialogs
- @nextcloud/files
- @nextcloud/l10n
- @nextcloud/password-confirmation
- @nextcloud/typings
- @nextcloud/vue
- @nextcloud/vue-select
- @nextcloud/webpack-vue-config
- @vue/component-compiler-utils
- @vue/test-utils
- cross-spawn
- elliptic
- express
- floating-vue
- http-proxy-middleware
- nanoid
- node-gettext
- path-to-regexp
- postcss
- vue
- vue-frag
- vue-loader
- vue-resize
- vue-template-compiler
- vue2-datepicker
- vuex
Fixed vulnerabilities
@chenfengyuan/vue-qrcode #
- Caused by vulnerable dependency:
- vue
 
- Affected versions: <=1.0.2
- Package usage:
- node_modules/@chenfengyuan/vue-qrcode
 
@nextcloud/dialogs #
- Caused by vulnerable dependency:
- @nextcloud/files
- @nextcloud/l10n
- @nextcloud/vue
- vue
- vue-frag
 
- Affected versions: >=2.0.0
- Package usage:
- node_modules/@nextcloud/dialogs
 
@nextcloud/files #
- Caused by vulnerable dependency:
- @nextcloud/l10n
 
- Affected versions: >=1.1.0
- Package usage:
- node_modules/@nextcloud/files
 
@nextcloud/l10n #
- Caused by vulnerable dependency:
- node-gettext
 
- Affected versions: >=1.1.0
- Package usage:
- node_modules/@nextcloud/l10n
 
@nextcloud/password-confirmation #
- Caused by vulnerable dependency:
- @nextcloud/l10n
- @nextcloud/vue
- vue
 
- Affected versions: >=3.0.0
- Package usage:
- node_modules/@nextcloud/password-confirmation
 
@nextcloud/typings #
- Caused by vulnerable dependency:
- vue
 
- Affected versions: 1.7.0 - 1.8.0
- Package usage:
- node_modules/@nextcloud/typings
 
@nextcloud/vue #
- Caused by vulnerable dependency:
- @nextcloud/l10n
- @nextcloud/vue-select
- floating-vue
- vue
- vue-frag
- vue2-datepicker
 
- Affected versions: *
- Package usage:
- node_modules/@nextcloud/vue
 
@nextcloud/vue-select #
- Caused by vulnerable dependency:
- vue
 
- Affected versions: *
- Package usage:
- node_modules/@nextcloud/vue-select
 
@nextcloud/webpack-vue-config #
- Caused by vulnerable dependency:
- vue
- vue-loader
- vue-template-compiler
 
- Affected versions: *
- Package usage:
- node_modules/@nextcloud/webpack-vue-config
 
@vue/component-compiler-utils #
- Caused by vulnerable dependency:
- postcss
 
- Affected versions: *
- Package usage:
- node_modules/@vue/component-compiler-utils
 
@vue/test-utils #
- Caused by vulnerable dependency:
- vue
- vue-template-compiler
 
- Affected versions: <=1.3.6
- Package usage:
- node_modules/@vue/test-utils
 
cross-spawn #
- Regular Expression Denial of Service (ReDoS) in cross-spawn
- Severity: high (CVSS 7.5)
- Reference: https://github.com/advisories/GHSA-3xgq-45jj-v275
- Affected versions: 7.0.0 - 7.0.4
- Package usage:
- node_modules/cross-spawn
 
elliptic #
- Valid ECDSA signatures erroneously rejected in Elliptic
- Severity: low (CVSS 4.8)
- Reference: https://github.com/advisories/GHSA-fc9h-whq2-v747
- Affected versions: <6.6.0
- Package usage:
- node_modules/elliptic
 
express #
- Caused by vulnerable dependency:
- path-to-regexp
 
- Affected versions: 4.0.0-rc1 - 4.21.1 || 5.0.0-alpha.1 - 5.0.0-beta.3
- Package usage:
- node_modules/express
 
floating-vue #
- Caused by vulnerable dependency:
- vue
- vue-resize
 
- Affected versions: <=1.0.0-beta.19
- Package usage:
- node_modules/floating-vue
 
http-proxy-middleware #
- Denial of service in http-proxy-middleware
- Severity: high (CVSS 7.5)
- Reference: https://github.com/advisories/GHSA-c7qv-q95q-8v27
- Affected versions: <2.0.7
- Package usage:
- node_modules/http-proxy-middleware
 
nanoid #
- Predictable results in nanoid generation when given non-integer values
- Severity: moderate (CVSS 4.3)
- Reference: https://github.com/advisories/GHSA-mwcw-c2x4-8c55
- Affected versions: <3.3.8
- Package usage:
- node_modules/nanoid
 
node-gettext #
- node-gettext vulnerable to Prototype Pollution
- Severity: high (CVSS 5.9)
- Reference: https://github.com/advisories/GHSA-g974-hxvm-x689
- Affected versions: *
- Package usage:
- node_modules/node-gettext
 
path-to-regexp #
- Unpatched path-to-regexpReDoS in 0.1.x
- Severity: moderate
- Reference: https://github.com/advisories/GHSA-rhx6-c78j-4q9w
- Affected versions: <0.1.12
- Package usage:
- node_modules/path-to-regexp
 
postcss #
- PostCSS line return parsing error
- Severity: moderate (CVSS 5.3)
- Reference: https://github.com/advisories/GHSA-7fh5-64p2-3v2j
- Affected versions: <8.4.31
- Package usage:
- node_modules/@vue/component-compiler-utils/node_modules/postcss
 
vue #
- ReDoS vulnerability in vue package that is exploitable through inefficient regex evaluation in the parseHTML function
- Severity: low (CVSS 3.7)
- Reference: https://github.com/advisories/GHSA-5j4c-8p2g-v4jx
- Affected versions: 2.0.0-alpha.1 - 2.7.16
- Package usage:
- node_modules/vue
 
vue-frag #
- Caused by vulnerable dependency:
- vue
 
- Affected versions: >=1.3.1
- Package usage:
- node_modules/vue-frag
 
vue-loader #
- Caused by vulnerable dependency:
- @vue/component-compiler-utils
 
- Affected versions: 15.0.0-beta.1 - 15.11.1
- Package usage:
- node_modules/vue-loader
 
vue-resize #
- Caused by vulnerable dependency:
- vue
 
- Affected versions: 0.4.0 - 1.0.1
- Package usage:
- node_modules/vue-resize
 
vue-template-compiler #
- vue-template-compiler vulnerable to client-side Cross-Site Scripting (XSS)
- Severity: moderate (CVSS 4.2)
- Reference: https://github.com/advisories/GHSA-g3ch-rx76-35fx
- Affected versions: >=2.0.0
- Package usage:
- node_modules/vue-template-compiler
 
vue2-datepicker #
- Caused by vulnerable dependency:
- vue
 
- Affected versions: <=1.9.8 || 3.0.2 - 3.11.1
- Package usage:
- node_modules/vue2-datepicker
 
vuex #
- Caused by vulnerable dependency:
- vue
 
- Affected versions: 3.1.3 - 3.6.2
- Package usage:
- node_modules/vuex