forked from lerlar/developer-tooling
-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathfs-report.txt
More file actions
202 lines (196 loc) Β· 48.6 KB
/
fs-report.txt
File metadata and controls
202 lines (196 loc) Β· 48.6 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
**Scan Type:** fs
**Target:** .
**Report Artifact Name:** developer-tooling-16172759059-fs-trivy
<details><summary>Click to expand</summary>
```
For OSS Maintainers: VEX Notice
--------------------------------
If you're an OSS maintainer and Trivy has detected vulnerabilities in your project that you believe are not actually exploitable, consider issuing a VEX (Vulnerability Exploitability eXchange) statement.
VEX allows you to communicate the actual status of vulnerabilities in your project, improving security transparency and reducing false positives for your users.
Learn more and start using VEX: https://trivy.dev/v0.64/docs/supply-chain/vex/repo#publishing-vex-documents
To disable this notice, set the TRIVY_DISABLE_VEX_NOTICE environment variable.
yarn.lock (yarn)
================
Total: 48 (UNKNOWN: 0, LOW: 13, MEDIUM: 10, HIGH: 21, CRITICAL: 4)
βββββββββββββββββββ¬ββββββββββββββββββββββ¬βββββββββββ¬βββββββββββ¬ββββββββββββββββββββ¬βββββββββββββββββββββββββββββββββββββ¬βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β Library β Vulnerability β Severity β Status β Installed Version β Fixed Version β Title β
βββββββββββββββββββΌββββββββββββββββββββββΌβββββββββββΌβββββββββββΌββββββββββββββββββββΌβββββββββββββββββββββββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β @babel/helpers β CVE-2025-27789 β MEDIUM β fixed β 7.21.0 β 7.26.10, 8.0.0-alpha.17 β Babel is a compiler for writing next generation JavaScript. β
β β β β β β β When using ...... β
β β β β β β β https://avd.aquasec.com/nvd/cve-2025-27789 β
βββββββββββββββββββ€ β β β β β β
β @babel/runtime β β β β β β β
β β β β β β β β
β β β β β β β β
βββββββββββββββββββΌββββββββββββββββββββββ€ β βββββββββββββββββββββΌβββββββββββββββββββββββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β @grpc/grpc-js β CVE-2024-37168 β β β 1.6.12 β 1.10.9, 1.9.15, 1.8.22 β grps-js: allocate memory for incoming messages well above β
β β β β β β β configured limits β
β β β β β β β https://avd.aquasec.com/nvd/cve-2024-37168 β
βββββββββββββββββββΌββββββββββββββββββββββΌβββββββββββ€ βββββββββββββββββββββΌβββββββββββββββββββββββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β axios β CVE-2025-27152 β HIGH β β 1.7.7 β 1.8.2, 0.30.0 β axios: Possible SSRF and Credential Leakage via Absolute URL β
β β β β β β β in axios Requests... β
β β β β β β β https://avd.aquasec.com/nvd/cve-2025-27152 β
βββββββββββββββββββΌββββββββββββββββββββββ€ β βββββββββββββββββββββΌβββββββββββββββββββββββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β base-x β CVE-2025-27611 β β β 3.0.9 β 5.0.1, 4.0.1, 3.0.11 β base-x: base-x homograph attack allows Unicode lookalike β
β β β β β β β characters to bypass validation. β
β β β β β β β https://avd.aquasec.com/nvd/cve-2025-27611 β
βββββββββββββββββββΌββββββββββββββββββββββ€ β βββββββββββββββββββββΌβββββββββββββββββββββββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β body-parser β CVE-2024-45590 β β β 1.20.1 β 1.20.3 β body-parser: Denial of Service Vulnerability in body-parser β
β β β β β β β https://avd.aquasec.com/nvd/cve-2024-45590 β
β β β β βββββββββββββββββββββ€ β β
β β β β β 1.20.2 β β β
β β β β β β β β
βββββββββββββββββββΌββββββββββββββββββββββΌβββββββββββ€ βββββββββββββββββββββΌβββββββββββββββββββββββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β brace-expansion β CVE-2025-5889 β LOW β β 1.1.11 β 2.0.2, 1.1.12, 3.0.1, 4.0.1 β brace-expansion: juliangruber brace-expansion index.js β
β β β β β β β expand redos β
β β β β β β β https://avd.aquasec.com/nvd/cve-2025-5889 β
β β β β βββββββββββββββββββββ€ β β
β β β β β 2.0.1 β β β
β β β β β β β β
β β β β β β β β
βββββββββββββββββββΌββββββββββββββββββββββΌβββββββββββ€ βββββββββββββββββββββΌβββββββββββββββββββββββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β braces β CVE-2024-4068 β HIGH β β 3.0.2 β 3.0.3 β braces: fails to limit the number of characters it can β
β β β β β β β handle β
β β β β β β β https://avd.aquasec.com/nvd/cve-2024-4068 β
βββββββββββββββββββΌββββββββββββββββββββββΌβββββββββββ€ βββββββββββββββββββββΌβββββββββββββββββββββββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β cookie β CVE-2024-47764 β LOW β β 0.5.0 β 0.7.0 β cookie: cookie accepts cookie name, path, and domain with β
β β β β β β β out of bounds... β
β β β β β β β https://avd.aquasec.com/nvd/cve-2024-47764 β
βββββββββββββββββββΌββββββββββββββββββββββΌβββββββββββ€ βββββββββββββββββββββΌβββββββββββββββββββββββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β cross-fetch β CVE-2022-1365 β MEDIUM β β 3.0.6 β 3.1.5, 2.2.6 β cross-fetch: Exposure of Private Personal Information to an β
β β β β β β β Unauthorized Actor β
β β β β β β β https://avd.aquasec.com/nvd/cve-2022-1365 β
βββββββββββββββββββΌββββββββββββββββββββββΌβββββββββββ€ βββββββββββββββββββββΌβββββββββββββββββββββββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β cross-spawn β CVE-2024-21538 β HIGH β β 7.0.3 β 7.0.5, 6.0.6 β cross-spawn: regular expression denial of service β
β β β β β β β https://avd.aquasec.com/nvd/cve-2024-21538 β
βββββββββββββββββββΌββββββββββββββββββββββΌβββββββββββ€ βββββββββββββββββββββΌβββββββββββββββββββββββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β elliptic β GHSA-vjh7-7g9h-fjfh β CRITICAL β β 6.5.4 β 6.6.1 β Elliptic's private key extraction in ECDSA upon signing a β
β β β β β β β malformed input (e.g.... β
β β β β β β β https://github.com/advisories/GHSA-vjh7-7g9h-fjfh β
β βββββββββββββββββββββββΌβββββββββββ€ β ββββββββββββββββββββββββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β β CVE-2024-42459 β LOW β β β 6.5.7 β elliptic: nodejs/elliptic: EDDSA signature malleability due β
β β β β β β β to missing signature length check β
β β β β β β β https://avd.aquasec.com/nvd/cve-2024-42459 β
β βββββββββββββββββββββββ€ β β β ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β β CVE-2024-42460 β β β β β elliptic: nodejs/elliptic: ECDSA signature malleability due β
β β β β β β β to missing checks β
β β β β β β β https://avd.aquasec.com/nvd/cve-2024-42460 β
β βββββββββββββββββββββββ€ β β β ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β β CVE-2024-42461 β β β β β elliptic: nodejs/elliptic: ECDSA implementation malleability β
β β β β β β β due to BER-enconded signatures being allowed β
β β β β β β β https://avd.aquasec.com/nvd/cve-2024-42461 β
β βββββββββββββββββββββββ€ β β ββββββββββββββββββββββββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β β CVE-2024-48948 β β β β 6.6.0 β elliptic: ECDSA signature verification error may reject β
β β β β β β β legitimate transactions β
β β β β β β β https://avd.aquasec.com/nvd/cve-2024-48948 β
β βββββββββββββββββββββββ€ β β ββββββββββββββββββββββββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β β CVE-2024-48949 β β β β 6.5.6 β elliptic: Missing Validation in Elliptic's EDDSA Signature β
β β β β β β β Verification β
β β β β β β β https://avd.aquasec.com/nvd/cve-2024-48949 β
βββββββββββββββββββΌββββββββββββββββββββββ€ β βββββββββββββββββββββΌβββββββββββββββββββββββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β es5-ext β CVE-2024-27088 β β β 0.10.62 β 0.10.63 β es5-ext contains ECMAScript 5 extensions. Passing functions β
β β β β β β β with very ... β
β β β β β β β https://avd.aquasec.com/nvd/cve-2024-27088 β
βββββββββββββββββββΌββββββββββββββββββββββΌβββββββββββ€ βββββββββββββββββββββΌβββββββββββββββββββββββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β express β CVE-2024-29041 β MEDIUM β β 4.18.2 β 4.19.2, 5.0.0-beta.3 β express: cause malformed URLs to be evaluated β
β β β β β β β https://avd.aquasec.com/nvd/cve-2024-29041 β
β βββββββββββββββββββββββΌβββββββββββ€ β ββββββββββββββββββββββββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β β CVE-2024-43796 β LOW β β β 4.20.0, 5.0.0 β express: Improper Input Handling in Express Redirects β
β β β β β β β https://avd.aquasec.com/nvd/cve-2024-43796 β
βββββββββββββββββββΌββββββββββββββββββββββΌβββββββββββΌβββββββββββΌββββββββββββββββββββΌβββββββββββββββββββββββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β ip β CVE-2024-29415 β HIGH β affected β 2.0.0 β β node-ip: Incomplete fix for CVE-2023-42282 β
β β β β β β β https://avd.aquasec.com/nvd/cve-2024-29415 β
β βββββββββββββββββββββββΌβββββββββββΌβββββββββββ€ ββββββββββββββββββββββββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β β CVE-2023-42282 β LOW β fixed β β 2.0.1, 1.1.9 β nodejs-ip: arbitrary code execution via the isPublic() β
β β β β β β β function β
β β β β β β β https://avd.aquasec.com/nvd/cve-2023-42282 β
βββββββββββββββββββΌββββββββββββββββββββββΌβββββββββββ€ βββββββββββββββββββββΌβββββββββββββββββββββββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β micromatch β CVE-2024-4067 β MEDIUM β β 4.0.5 β 4.0.8 β micromatch: vulnerable to Regular Expression Denial of β
β β β β β β β Service β
β β β β β β β https://avd.aquasec.com/nvd/cve-2024-4067 β
βββββββββββββββββββΌββββββββββββββββββββββΌβββββββββββ€ βββββββββββββββββββββΌβββββββββββββββββββββββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β node-fetch β CVE-2022-0235 β HIGH β β 2.6.1 β 3.1.1, 2.6.7 β node-fetch: exposure of sensitive information to an β
β β β β β β β unauthorized actor β
β β β β β β β https://avd.aquasec.com/nvd/cve-2022-0235 β
βββββββββββββββββββΌββββββββββββββββββββββ€ β βββββββββββββββββββββΌβββββββββββββββββββββββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β path-to-regexp β CVE-2024-45296 β β β 0.1.7 β 1.9.0, 0.1.10, 8.0.0, 3.3.0, 6.3.0 β path-to-regexp: Backtracking regular expressions cause ReDoS β
β β β β β β β https://avd.aquasec.com/nvd/cve-2024-45296 β
β βββββββββββββββββββββββ€ β β ββββββββββββββββββββββββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β β CVE-2024-52798 β β β β 0.1.12 β path-to-regexp: path-to-regexp Unpatched `path-to-regexp` β
β β β β β β β ReDoS in 0.1.x β
β β β β β β β https://avd.aquasec.com/nvd/cve-2024-52798 β
β βββββββββββββββββββββββ€ β βββββββββββββββββββββΌβββββββββββββββββββββββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β β CVE-2024-45296 β β β 2.4.0 β 1.9.0, 0.1.10, 8.0.0, 3.3.0, 6.3.0 β path-to-regexp: Backtracking regular expressions cause ReDoS β
β β β β β β β https://avd.aquasec.com/nvd/cve-2024-45296 β
βββββββββββββββββββΌββββββββββββββββββββββΌβββββββββββ€ βββββββββββββββββββββΌβββββββββββββββββββββββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β pbkdf2 β CVE-2025-6545 β CRITICAL β β 3.1.2 β 3.1.3 β pbkdf2: pbkdf2 silently returns predictable key material β
β β β β β β β https://avd.aquasec.com/nvd/cve-2025-6545 β
β βββββββββββββββββββββββ€ β β β ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β β CVE-2025-6547 β β β β β pbkdf2: pbkdf2 silently returns static keys β
β β β β β β β https://avd.aquasec.com/nvd/cve-2025-6547 β
βββββββββββββββββββΌββββββββββββββββββββββ€ β βββββββββββββββββββββΌβββββββββββββββββββββββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β protobufjs β CVE-2023-36665 β β β 6.11.3 β 7.2.5, 6.11.4 β protobufjs: prototype pollution using user-controlled β
β β β β β β β protobuf message β
β β β β β β β https://avd.aquasec.com/nvd/cve-2023-36665 β
βββββββββββββββββββΌββββββββββββββββββββββΌβββββββββββΌβββββββββββΌββββββββββββββββββββΌβββββββββββββββββββββββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β request β CVE-2023-28155 β MEDIUM β affected β 2.88.2 β β The Request package through 2.88.1 for Node.js allows a β
β β β β β β β bypass of SSRF... β
β β β β β β β https://avd.aquasec.com/nvd/cve-2023-28155 β
βββββββββββββββββββΌββββββββββββββββββββββΌβββββββββββΌβββββββββββΌββββββββββββββββββββΌβββββββββββββββββββββββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β secp256k1 β CVE-2024-48930 β HIGH β fixed β 4.0.3 β 5.0.1, 4.0.4, 3.8.1 β secp256k1-node allows private key extraction over ECDH β
β β β β β β β https://avd.aquasec.com/nvd/cve-2024-48930 β
β β β β βββββββββββββββββββββ€ β β
β β β β β 5.0.0 β β β
β β β β β β β β
βββββββββββββββββββΌββββββββββββββββββββββΌβββββββββββ€ βββββββββββββββββββββΌβββββββββββββββββββββββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β send β CVE-2024-43799 β LOW β β 0.18.0 β 0.19.0 β send: Code Execution Vulnerability in Send Library β
β β β β β β β https://avd.aquasec.com/nvd/cve-2024-43799 β
βββββββββββββββββββΌββββββββββββββββββββββ€ β βββββββββββββββββββββΌβββββββββββββββββββββββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β serve-static β CVE-2024-43800 β β β 1.15.0 β 1.16.0, 2.1.0 β serve-static: Improper Sanitization in serve-static β
β β β β β β β https://avd.aquasec.com/nvd/cve-2024-43800 β
βββββββββββββββββββΌββββββββββββββββββββββΌβββββββββββ€ βββββββββββββββββββββΌβββββββββββββββββββββββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β tar β CVE-2024-28863 β MEDIUM β β 4.4.19 β 6.2.1 β node-tar: denial of service while parsing a tar file due to β
β β β β β β β lack... β
β β β β β β β https://avd.aquasec.com/nvd/cve-2024-28863 β
β β β β βββββββββββββββββββββ€ β β
β β β β β 6.1.13 β β β
β β β β β β β β
β β β β β β β β
βββββββββββββββββββΌββββββββββββββββββββββΌβββββββββββ€ βββββββββββββββββββββΌβββββββββββββββββββββββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β tar-fs β CVE-2024-12905 β HIGH β β 1.16.3 β 1.16.4, 2.1.2, 3.0.7 β tar-fs: link following and path traversal via maliciously β
β β β β β β β crafted tar file β
β β β β β β β https://avd.aquasec.com/nvd/cve-2024-12905 β
β βββββββββββββββββββββββ€ β β ββββββββββββββββββββββββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β β CVE-2025-48387 β β β β 1.16.5, 2.1.3, 3.0.9 β tar-fs: tar-fs has issue where extract can write outside the β
β β β β β β β specified dir... β
β β β β β β β https://avd.aquasec.com/nvd/cve-2025-48387 β
β βββββββββββββββββββββββ€ β βββββββββββββββββββββΌβββββββββββββββββββββββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β β CVE-2024-12905 β β β 2.1.1 β 1.16.4, 2.1.2, 3.0.7 β tar-fs: link following and path traversal via maliciously β
β β β β β β β crafted tar file β
β β β β β β β https://avd.aquasec.com/nvd/cve-2024-12905 β
β βββββββββββββββββββββββ€ β β ββββββββββββββββββββββββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β β CVE-2025-48387 β β β β 1.16.5, 2.1.3, 3.0.9 β tar-fs: tar-fs has issue where extract can write outside the β
β β β β β β β specified dir... β
β β β β β β β https://avd.aquasec.com/nvd/cve-2025-48387 β
βββββββββββββββββββΌββββββββββββββββββββββΌβββββββββββ€ βββββββββββββββββββββΌβββββββββββββββββββββββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β tough-cookie β CVE-2023-26136 β MEDIUM β β 2.5.0 β 4.1.3 β tough-cookie: prototype pollution in cookie memstore β
β β β β β β β https://avd.aquasec.com/nvd/cve-2023-26136 β
βββββββββββββββββββΌββββββββββββββββββββββΌβββββββββββ€ βββββββββββββββββββββΌβββββββββββββββββββββββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β ws β CVE-2024-37890 β HIGH β β 3.3.3 β 5.2.4, 6.2.3, 7.5.10, 8.17.1 β nodejs-ws: denial of service when handling a request with β
β β β β β β β many HTTP headers... β
β β β β β β β https://avd.aquasec.com/nvd/cve-2024-37890 β
β β β β βββββββββββββββββββββ€ β β
β β β β β 7.4.6 β β β
β β β β β β β β
β β β β β β β β
β β β β βββββββββββββββββββββ€ β β
β β β β β 8.16.0 β β β
β β β β β β β β
β β β β β β β β
β β β β βββββββββββββββββββββ€ β β
β β β β β 8.2.3 β β β
β β β β β β β β
β β β β β β β β
βββββββββββββββββββ΄ββββββββββββββββββββββ΄βββββββββββ΄βββββββββββ΄ββββββββββββββββββββ΄βββββββββββββββββββββββββββββββββββββ΄βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
```
</details>