Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

npm audit finds 7 vulnerabilities (1 low, 5 moderate, 1 high) #39

Open
wanton7 opened this issue Jan 13, 2019 · 0 comments
Open

npm audit finds 7 vulnerabilities (1 low, 5 moderate, 1 high) #39

wanton7 opened this issue Jan 13, 2019 · 0 comments

Comments

@wanton7
Copy link

wanton7 commented Jan 13, 2019

npm audit returns following vulnerabilities for marko-starter 2.0.4.

                       === npm audit security report ===


                                 Manual Review
             Some vulnerabilities require your attention to resolve

          Visit https://go.npm.me/audit-guide for additional guidance


  High            Regular Expression Denial of Service

  Package         fresh

  Patched in      >= 0.5.2

  Dependency of   marko-starter

  Path            marko-starter > marko-starter-generic-server > send > fresh

  More info       https://nodesecurity.io/advisories/526


  Moderate        Prototype pollution

  Package         hoek

  Patched in      > 4.2.0 < 5.0.0 || >= 5.0.3

  Dependency of   marko-starter

  Path            marko-starter > marko-starter-lasso > lasso-less > less >
                  request > hawk > boom > hoek

  More info       https://nodesecurity.io/advisories/566


  Moderate        Prototype pollution

  Package         hoek

  Patched in      > 4.2.0 < 5.0.0 || >= 5.0.3

  Dependency of   marko-starter

  Path            marko-starter > marko-starter-lasso > lasso-less > less >
                  request > hawk > cryptiles > boom > hoek

  More info       https://nodesecurity.io/advisories/566


  Moderate        Prototype pollution

  Package         hoek

  Patched in      > 4.2.0 < 5.0.0 || >= 5.0.3

  Dependency of   marko-starter

  Path            marko-starter > marko-starter-lasso > lasso-less > less >
                  request > hawk > hoek

  More info       https://nodesecurity.io/advisories/566


  Moderate        Prototype pollution

  Package         hoek

  Patched in      > 4.2.0 < 5.0.0 || >= 5.0.3

  Dependency of   marko-starter

  Path            marko-starter > marko-starter-lasso > lasso-less > less >
                  request > hawk > sntp > hoek

  More info       https://nodesecurity.io/advisories/566


  Moderate        Regular Expression Denial of Service

  Package         mime

  Patched in      >= 1.4.1 < 2.0.0 || >= 2.0.3

  Dependency of   marko-starter

  Path            marko-starter > marko-starter-generic-server > send > mime

  More info       https://nodesecurity.io/advisories/535


  Low             Regular Expression Denial of Service

  Package         debug

  Patched in      >= 2.6.9 < 3.0.0 || >= 3.1.0

  Dependency of   marko-starter

  Path            marko-starter > marko-starter-generic-server > send > debug

  More info       https://nodesecurity.io/advisories/534

found 7 vulnerabilities (1 low, 5 moderate, 1 high) in 3393 scanned packages
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant