Skip to content

Conversation

@elOtta1223
Copy link
Owner

snyk-top-banner

Snyk has created this PR to fix 86 vulnerabilities in the npm dependencies of this project.

Snyk changed the following file(s):

  • package.json

Vulnerabilities that will be fixed with an upgrade:

Issue Score
high severity Arbitrary File Write
SNYK-JS-TAR-1579152
  ****  
high severity Arbitrary File Write
SNYK-JS-TAR-1579155
  ****  
medium severity Uncontrolled Resource Consumption ('Resource Exhaustion')
SNYK-JS-TAR-6476909
  ****  
medium severity Prototype Pollution
SNYK-JS-TOUGHCOOKIE-5672873
  ****  
high severity Denial of Service (DoS)
SNYK-JS-TRIMNEWLINES-1298042
  ****  
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-UGLIFYJS-1727251
  ****  
critical severity Predictable Value Range from Previous Values
SNYK-JS-FORMDATA-10841150
  791  
high severity NULL Pointer Dereference
SNYK-JS-NODESASS-535500
  761  
high severity NULL Pointer Dereference
SNYK-JS-NODESASS-535505
  761  
high severity NULL Pointer Dereference
SNYK-JS-NODESASS-540974
  761  
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-CROSSSPAWN-8303230
  756  
high severity Remote Code Execution (RCE)
SNYK-JS-EJS-2803307
  726  
high severity Out-of-bounds Read
SNYK-JS-NODESASS-535501
  726  
high severity Out-of-bounds Read
SNYK-JS-NODESASS-540956
  726  
high severity Out-of-bounds Read
SNYK-JS-NODESASS-540996
  726  
critical severity Sandbox Bypass
npm:constantinople:20180421
  714  
high severity Prototype Pollution
SNYK-JS-LODASH-6139239
  696  
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-SEMVER-3247795
  696  
high severity Regular Expression Denial of Service (ReDoS)
npm:marked:20180225
  696  
high severity Prototype Pollution
SNYK-JS-LODASH-450202
  686  
high severity Prototype Pollution
SNYK-JS-LODASH-608086
  686  
high severity Prototype Pollution
SNYK-JS-LODASH-73638
  686  
high severity Code Injection
SNYK-JS-LODASH-1040724
  681  
high severity Use After Free
SNYK-JS-NODESASS-541000
  654  
high severity Cross-site Scripting (XSS)
npm:marked:20150520
  654  
medium severity Out-of-Bounds
SNYK-JS-NODESASS-535498
  646  
medium severity NULL Pointer Dereference
SNYK-JS-NODESASS-535502
  646  
medium severity Resource Exhaustion
SNYK-JS-NODESASS-535504
  646  
medium severity Denial of Service (DoS)
SNYK-JS-NODESASS-540978
  646  
medium severity Denial of Service (DoS)
SNYK-JS-NODESASS-540980
  646  
medium severity Denial of Service (DoS)
SNYK-JS-NODESASS-540982
  646  
medium severity Out-of-bounds Read
SNYK-JS-NODESASS-540990
  646  
medium severity Out-of-Bounds
SNYK-JS-NODESASS-540998
  646  
medium severity Out-of-bounds Read
SNYK-JS-NODESASS-541002
  646  
medium severity Server-side Request Forgery (SSRF)
SNYK-JS-REQUEST-3361831
  646  
high severity Arbitrary File Write
SNYK-JS-TAR-1579147
  639  
medium severity Prototype Pollution
npm:lodash:20180130
  636  
medium severity Missing Release of Resource after Effective Lifetime
SNYK-JS-INFLIGHT-6095116
  631  
high severity Improper minification of non-boolean comparisons
npm:uglify-js:20150824
  629  
high severity Arbitrary File Overwrite
SNYK-JS-TAR-1536528
  624  
high severity Arbitrary File Overwrite
SNYK-JS-TAR-1536531
  624  
high severity Arbitrary Code Execution
npm:ejs:20161128
  619  
high severity Uncontrolled Recursion
SNYK-JS-NODESASS-535503
  600  
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-MINIMATCH-1019388
  589  
high severity Uncontrolled Recursion
SNYK-JS-NODESASS-540960
  589  
high severity Out-of-bounds Read
SNYK-JS-NODESASS-540962
  589  
high severity Improper Input Validation
SNYK-JS-NODESASS-540966
  589  
high severity Improper Input Validation
SNYK-JS-NODESASS-540968
  589  
high severity Uncontrolled Recursion
SNYK-JS-NODESASS-540970
  589  
high severity Out-of-bounds Read
SNYK-JS-NODESASS-540972
  589  
high severity Out-of-bounds Read
SNYK-JS-NODESASS-540986
  589  
high severity Denial of Service (DoS)
SNYK-JS-NODESASS-540988
  589  
high severity Cross-site Scripting (XSS)
npm:marked:20170112
  589  
high severity Cross-site Scripting (XSS)
npm:marked:20170815
  589  
high severity Regular Expression Denial of Service (ReDoS)
npm:marked:20170907
  589  
high severity Regular Expression Denial of Service (ReDoS)
npm:minimatch:20160620
  589  
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-BROWSERSLIST-1090194
  586  
medium severity Improper Control of Dynamically-Managed Code Resources
SNYK-JS-EJS-6689533
  586  
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-HTMLMINIFIER-3091181
  586  
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-LODASH-1018905
  586  
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-MARKED-2342073
  586  
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-MARKED-2342082
  586  
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-POSTCSS-1255640
  586  
medium severity Out-of-bounds Read
SNYK-JS-NODESASS-535499
  550  
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-LODASH-73639
  541  
medium severity Out-of-bounds Read
SNYK-JS-NODESASS-540984
  539  
medium severity NULL Pointer Dereference
SNYK-JS-NODESASS-540994
  539  
medium severity Out-of-bounds Read
SNYK-JS-NODESASS-540958
  536  
medium severity Uncontrolled Recursion
SNYK-JS-NODESASS-540964
  536  
medium severity NULL Pointer Dereference
SNYK-JS-NODESASS-540992
  536  
medium severity Arbitrary Code Injection
SNYK-JS-EJS-1049328
  526  
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-MARKED-584281
  520  
medium severity Denial of Service (DoS)
SNYK-JS-NODESASS-542662
  509  
medium severity Cross-site Scripting (XSS)
npm:ejs:20161130
  509  
medium severity Denial of Service (DoS)
npm:ejs:20161130-1
  509  
low severity Regular Expression Denial of Service (ReDoS)
npm:clean-css:20180306
  506  
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-MARKED-174116
  479  
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-MARKED-451540
  479  
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-MINIMATCH-3050818
  479  
medium severity Improper Certificate Validation
SNYK-JS-NODESASS-1059081
  479  
medium severity Improper Input Validation
SNYK-JS-POSTCSS-5926692
  479  
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-SCSSTOKENIZER-2339884
  479  
medium severity Regular Expression Denial of Service (ReDoS)
npm:uglify-js:20151024
  479  
medium severity Cross-site Scripting (XSS)
npm:marked:20170815-1
  454  
low severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-TAR-1536758
  410  
low severity Insecure use of /tmp folder
npm:cli:20160615
  354  

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Regular Expression Denial of Service (ReDoS)
🦉 Arbitrary Code Injection
🦉 Improper Control of Dynamically-Managed Code Resources
🦉 More lessons are available in Snyk Learn

The following vulnerabilities are fixed with an upgrade:
- https://snyk.io/vuln/SNYK-JS-TAR-1579152
- https://snyk.io/vuln/SNYK-JS-TAR-1579155
- https://snyk.io/vuln/SNYK-JS-TAR-6476909
- https://snyk.io/vuln/SNYK-JS-TOUGHCOOKIE-5672873
- https://snyk.io/vuln/SNYK-JS-TRIMNEWLINES-1298042
- https://snyk.io/vuln/SNYK-JS-UGLIFYJS-1727251
- https://snyk.io/vuln/SNYK-JS-FORMDATA-10841150
- https://snyk.io/vuln/SNYK-JS-NODESASS-535500
- https://snyk.io/vuln/SNYK-JS-NODESASS-535505
- https://snyk.io/vuln/SNYK-JS-NODESASS-540974
- https://snyk.io/vuln/SNYK-JS-CROSSSPAWN-8303230
- https://snyk.io/vuln/SNYK-JS-EJS-2803307
- https://snyk.io/vuln/SNYK-JS-NODESASS-535501
- https://snyk.io/vuln/SNYK-JS-NODESASS-540956
- https://snyk.io/vuln/SNYK-JS-NODESASS-540996
- https://snyk.io/vuln/npm:constantinople:20180421
- https://snyk.io/vuln/SNYK-JS-LODASH-6139239
- https://snyk.io/vuln/SNYK-JS-SEMVER-3247795
- https://snyk.io/vuln/npm:marked:20180225
- https://snyk.io/vuln/SNYK-JS-LODASH-450202
- https://snyk.io/vuln/SNYK-JS-LODASH-608086
- https://snyk.io/vuln/SNYK-JS-LODASH-73638
- https://snyk.io/vuln/SNYK-JS-LODASH-1040724
- https://snyk.io/vuln/SNYK-JS-NODESASS-541000
- https://snyk.io/vuln/npm:marked:20150520
- https://snyk.io/vuln/SNYK-JS-NODESASS-535498
- https://snyk.io/vuln/SNYK-JS-NODESASS-535502
- https://snyk.io/vuln/SNYK-JS-NODESASS-535504
- https://snyk.io/vuln/SNYK-JS-NODESASS-540978
- https://snyk.io/vuln/SNYK-JS-NODESASS-540980
- https://snyk.io/vuln/SNYK-JS-NODESASS-540982
- https://snyk.io/vuln/SNYK-JS-NODESASS-540990
- https://snyk.io/vuln/SNYK-JS-NODESASS-540998
- https://snyk.io/vuln/SNYK-JS-NODESASS-541002
- https://snyk.io/vuln/SNYK-JS-REQUEST-3361831
- https://snyk.io/vuln/SNYK-JS-TAR-1579147
- https://snyk.io/vuln/npm:lodash:20180130
- https://snyk.io/vuln/SNYK-JS-INFLIGHT-6095116
- https://snyk.io/vuln/npm:uglify-js:20150824
- https://snyk.io/vuln/SNYK-JS-TAR-1536528
- https://snyk.io/vuln/SNYK-JS-TAR-1536531
- https://snyk.io/vuln/npm:ejs:20161128
- https://snyk.io/vuln/SNYK-JS-NODESASS-535503
- https://snyk.io/vuln/SNYK-JS-MINIMATCH-1019388
- https://snyk.io/vuln/SNYK-JS-NODESASS-540960
- https://snyk.io/vuln/SNYK-JS-NODESASS-540962
- https://snyk.io/vuln/SNYK-JS-NODESASS-540966
- https://snyk.io/vuln/SNYK-JS-NODESASS-540968
- https://snyk.io/vuln/SNYK-JS-NODESASS-540970
- https://snyk.io/vuln/SNYK-JS-NODESASS-540972
- https://snyk.io/vuln/SNYK-JS-NODESASS-540986
- https://snyk.io/vuln/SNYK-JS-NODESASS-540988
- https://snyk.io/vuln/npm:marked:20170112
- https://snyk.io/vuln/npm:marked:20170815
- https://snyk.io/vuln/npm:marked:20170907
- https://snyk.io/vuln/npm:minimatch:20160620
- https://snyk.io/vuln/SNYK-JS-BROWSERSLIST-1090194
- https://snyk.io/vuln/SNYK-JS-EJS-6689533
- https://snyk.io/vuln/SNYK-JS-HTMLMINIFIER-3091181
- https://snyk.io/vuln/SNYK-JS-LODASH-1018905
- https://snyk.io/vuln/SNYK-JS-MARKED-2342073
- https://snyk.io/vuln/SNYK-JS-MARKED-2342082
- https://snyk.io/vuln/SNYK-JS-POSTCSS-1255640
- https://snyk.io/vuln/SNYK-JS-NODESASS-535499
- https://snyk.io/vuln/SNYK-JS-LODASH-73639
- https://snyk.io/vuln/SNYK-JS-NODESASS-540984
- https://snyk.io/vuln/SNYK-JS-NODESASS-540994
- https://snyk.io/vuln/SNYK-JS-NODESASS-540958
- https://snyk.io/vuln/SNYK-JS-NODESASS-540964
- https://snyk.io/vuln/SNYK-JS-NODESASS-540992
- https://snyk.io/vuln/SNYK-JS-EJS-1049328
- https://snyk.io/vuln/SNYK-JS-MARKED-584281
- https://snyk.io/vuln/SNYK-JS-NODESASS-542662
- https://snyk.io/vuln/npm:ejs:20161130
- https://snyk.io/vuln/npm:ejs:20161130-1
- https://snyk.io/vuln/npm:clean-css:20180306
- https://snyk.io/vuln/SNYK-JS-MARKED-174116
- https://snyk.io/vuln/SNYK-JS-MARKED-451540
- https://snyk.io/vuln/SNYK-JS-MINIMATCH-3050818
- https://snyk.io/vuln/SNYK-JS-NODESASS-1059081
- https://snyk.io/vuln/SNYK-JS-POSTCSS-5926692
- https://snyk.io/vuln/SNYK-JS-SCSSTOKENIZER-2339884
- https://snyk.io/vuln/npm:uglify-js:20151024
- https://snyk.io/vuln/npm:marked:20170815-1
- https://snyk.io/vuln/SNYK-JS-TAR-1536758
- https://snyk.io/vuln/npm:cli:20160615
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants