Blockstream / Blockstream/esplora

Found 49 vulnerabilities (12 moderate, 37 high) | 12 vulnerabilities require manual review.

Open
#354 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
JavaScript
Stars
1.3k
Forks
514
Avg merge
1d 10h
Merged PRs (30d)
16

Description

root@d4c6842678e0:~/esplora# npm audit

=== npm audit security report ===

# Run npm update path-parse --depth 7 to resolve 5 vulnerabilities

Moderate Regular Expression Denial of Service in path-parse

Package path-parse

Dependency of browserify

Path browserify > resolve > path-parse

More info https://github.com/advisories/GHSA-hj48-42vr-x3v9


Moderate Regular Expression Denial of Service in path-parse

Package path-parse

Dependency of browserify

Path browserify > browser-resolve > resolve > path-parse

More info https://github.com/advisories/GHSA-hj48-42vr-x3v9


Moderate Regular Expression Denial of Service in path-parse

Package path-parse

Dependency of browserify

Path browserify > module-deps > browser-resolve > resolve >
path-parse

More info https://github.com/advisories/GHSA-hj48-42vr-x3v9


Moderate Regular Expression Denial of Service in path-parse

Package path-parse

Dependency of browserify-middleware [dev]

Path browserify-middleware > browserify > module-deps >
browser-resolve > resolve > path-parse

More info https://github.com/advisories/GHSA-hj48-42vr-x3v9


Moderate Regular Expression Denial of Service in path-parse

Package path-parse

Dependency of browserify-middleware [dev]

Path browserify-middleware > watchify > browserify > module-deps
> browser-resolve > resolve > path-parse

More info https://github.com/advisories/GHSA-hj48-42vr-x3v9

# Run npm update null --depth 2 to resolve 1 vulnerability

High Regular expression denial of service

Package glob-parent

Dependency of @babel/cli

Path @babel/cli > @nicolo-ribaudo/chokidar-2 > glob-parent

More info https://github.com/advisories/GHSA-ww39-953v-wcq6

# Run npm update glob-parent --depth 3 to resolve 1 vulnerability

High Regular expression denial of service

Package glob-parent

Dependency of @babel/cli

Path @babel/cli > chokidar > glob-parent

More info https://github.com/advisories/GHSA-ww39-953v-wcq6

# Run npm update browserslist --depth 3 to resolve 1 vulnerability

Moderate Regular Expression Denial of Service in browserslist

Package browserslist

Dependency of @babel/preset-env

Path @babel/preset-env > @babel/helper-compilation-targets >
browserslist

More info https://github.com/advisories/GHSA-w8qv-6jwh-64r5

# Run npm update lodash --depth 9 to resolve 8 vulnerabilities

High Command Injection in lodash

Package lodash

Dependency of @babel/cli

Path @babel/cli > lodash

More info https://github.com/advisories/GHSA-35jh-r3h4-6jhm


High Command Injection in lodash

Package lodash

Dependency of @babel/core

Path @babel/core > @babel/types > lodash

More info https://github.com/advisories/GHSA-35jh-r3h4-6jhm


High Command Injection in lodash

Package lodash

Dependency of @babel/core

Path @babel/core > @babel/generator > @babel/types > lodash

More info https://github.com/advisories/GHSA-35jh-r3h4-6jhm


High Command Injection in lodash

Package lodash

Dependency of @babel/core

Path @babel/core > @babel/traverse > @babel/generator >
@babel/types > lodash

More info https://github.com/advisories/GHSA-35jh-r3h4-6jhm


High Command Injection in lodash

Package lodash

Dependency of @babel/core

Path @babel/core > @babel/helper-module-transforms >
@babel/traverse > @babel/generator > @babel/types > lodash

More info https://github.com/advisories/GHSA-35jh-r3h4-6jhm


High Command Injection in lodash

Package lodash

Dependency of @babel/core

Path @babel/core > @babel/helper-module-transforms >
@babel/helper-replace-supers > @babel/traverse >
@babel/generator > @babel/types > lodash

More info https://github.com/advisories/GHSA-35jh-r3h4-6jhm


High Command Injection in lodash

Package lodash

Dependency of @babel/preset-env

Path @babel/preset-env > @babel/plugin-transform-modules-amd >
@babel/helper-module-transforms >
@babel/helper-replace-supers > @babel/traverse >
@babel/generator > @babel/types > lodash

More info https://github.com/advisories/GHSA-35jh-r3h4-6jhm


High Command Injection in lodash

Package lodash

Dependency of @babel/preset-env

Path @babel/preset-env > @babel/plugin-transform-modules-amd >
@babel/helper-module-transforms >
@babel/helper-replace-supers > @babel/traverse >
@babel/helper-function-name >
@babel/helper-get-function-arity > @babel/types > lodash

More info https://github.com/advisories/GHSA-35jh-r3h4-6jhm

# Run npm update elliptic --depth 6 to resolve 3 vulnerabilities

Moderate Use of a Broken or Risky Cryptographic Algorithm

Package elliptic

Dependency of browserify

Path browserify > crypto-browserify > browserify-sign > elliptic

More info https://github.com/advisories/GHSA-r9p9-mrjm-926w


Moderate Use of a Broken or Risky Cryptographic Algorithm

Package elliptic

Dependency of browserify-middleware [dev]

Path browserify-middleware > browserify > crypto-browserify >
browserify-sign > elliptic

More info https://github.com/advisories/GHSA-r9p9-mrjm-926w


Moderate Use of a Broken or Risky Cryptographic Algorithm

Package elliptic

Dependency of browserify-middleware [dev]

Path browserify-middleware > watchify > browserify >
crypto-browserify > browserify-sign > elliptic

More info https://github.com/advisories/GHSA-r9p9-mrjm-926w

# Run npm update pug-code-gen --depth 2 to resolve 1 vulnerability

High Remote code execution via the `pretty` option.

Package pug-code-gen

Dependency of pug

Path pug > pug-code-gen

More info https://github.com/advisories/GHSA-p493-635q-r6gr

# Run npm update pug --depth 1 to resolve 1 vulnerability

High Remote code execution via the `pretty` option.

Package pug

Dependency of pug

Path pug

More info https://github.com/advisories/GHSA-p493-635q-r6gr

# Run npm update kind-of --depth 13 to resolve 16 vulnerabilities

High Validation Bypass in kind-of

Package kind-of

Dependency of @babel/cli

Path @babel/cli > @nicolo-ribaudo/chokidar-2 > braces >
snapdragon > base > define-property > is-descriptor >
kind-of

More info https://github.com/advisories/GHSA-6c8f-qphg-qjgp


High Validation Bypass in kind-of

Package kind-of

Dependency of @babel/cli

Path @babel/cli > @nicolo-ribaudo/chokidar-2 > braces >
snapdragon > base > define-property > is-descriptor >
is-accessor-descriptor > kind-of

More info https://github.com/advisories/GHSA-6c8f-qphg-qjgp


High Validation Bypass in kind-of

Package kind-of

Dependency of patch-package

Path patch-package > find-yarn-workspace-root > micromatch >
braces > snapdragon > base > define-property > is-descriptor
> is-accessor-descriptor > kind-of

More info https://github.com/advisories/GHSA-6c8f-qphg-qjgp


High Validation Bypass in kind-of

Package kind-of

Dependency of @babel/cli

Path @babel/cli > @nicolo-ribaudo/chokidar-2 > anymatch >
micromatch > braces > snapdragon > base > define-property >
is-descriptor > is-accessor-descriptor > kind-of

More info https://github.com/advisories/GHSA-6c8f-qphg-qjgp


High Validation Bypass in kind-of

Package kind-of

Dependency of @babel/cli

Path @babel/cli > @nicolo-ribaudo/chokidar-2 > anymatch >
micromatch > extglob > expand-brackets > snapdragon > base >
define-property > is-descriptor > is-accessor-descriptor >
kind-of

More info https://github.com/advisories/GHSA-6c8f-qphg-qjgp


High Validation Bypass in kind-of

Package kind-of

Dependency of browserify-middleware [dev]

Path browserify-middleware > watchify > chokidar > readdirp >
micromatch > extglob > expand-brackets > snapdragon > base >
define-property > is-descriptor > is-accessor-descriptor >
kind-of

More info https://github.com/advisories/GHSA-6c8f-qphg-qjgp


High Validation Bypass in kind-of

Package kind-of

Dependency of @babel/cli

Path @babel/cli > @nicolo-ribaudo/chokidar-2 > braces >
snapdragon-node > define-property > is-descriptor > kind-of

More info https://github.com/advisories/GHSA-6c8f-qphg-qjgp


High Validation Bypass in kind-of

Package kind-of

Dependency of @babel/cli

Path @babel/cli > @nicolo-ribaudo/chokidar-2 > braces >
snapdragon-node > define-property > is-descriptor >
is-accessor-descriptor > kind-of

More info https://github.com/advisories/GHSA-6c8f-qphg-qjgp


High Validation Bypass in kind-of

Package kind-of

Dependency of patch-package

Path patch-package > find-yarn-workspace-root > micromatch >
braces > snapdragon-node > define-property > is-descriptor >
is-accessor-descriptor > kind-of

More info https://github.com/advisories/GHSA-6c8f-qphg-qjgp


High Validation Bypass in kind-of

Package kind-of

Dependency of @babel/cli

Path @babel/cli > @nicolo-ribaudo/chokidar-2 > anymatch >
micromatch > braces > snapdragon-node > define-property >
is-descriptor > is-accessor-descriptor > kind-of

More info https://github.com/advisories/GHSA-6c8f-qphg-qjgp


High Validation Bypass in kind-of

Package kind-of

Dependency of browserify-middleware [dev]

Path browserify-middleware > watchify > chokidar > readdirp >
micromatch > braces > snapdragon-node > define-property >
is-descriptor > is-accessor-descriptor > kind-of

More info https://github.com/advisories/GHSA-6c8f-qphg-qjgp


High Validation Bypass in kind-of

Package kind-of

Dependency of browserify-middleware [dev]

Path browserify-middleware > watchify > anymatch > micromatch >
kind-of

More info https://github.com/advisories/GHSA-6c8f-qphg-qjgp


High Validation Bypass in kind-of

Package kind-of

Dependency of browserify-middleware [dev]

Path browserify-middleware > watchify > chokidar > anymatch >
micromatch > kind-of

More info https://github.com/advisories/GHSA-6c8f-qphg-qjgp


High Validation Bypass in kind-of

Package kind-of

Dependency of browserify-middleware [dev]

Path browserify-middleware > watchify > anymatch > micromatch >
extglob > define-property > is-descriptor > kind-of

More info https://github.com/advisories/GHSA-6c8f-qphg-qjgp


High Validation Bypass in kind-of

Package kind-of

Dependency of browserify-middleware [dev]

Path browserify-middleware > watchify > anymatch > micromatch >
extglob > define-property > is-descriptor >
is-accessor-descriptor > kind-of

More info https://github.com/advisories/GHSA-6c8f-qphg-qjgp


High Validation Bypass in kind-of

Package kind-of

Dependency of browserify-middleware [dev]

Path browserify-middleware > watchify > chokidar > anymatch >
micromatch > extglob > define-property > is-descriptor >
is-accessor-descriptor > kind-of

More info https://github.com/advisories/GHSA-6c8f-qphg-qjgp


Manual Review
Some vulnerabilities require your attention to resolve

Visit https://go.npm.me/audit-guide for additional guidance


High Arbitrary File Creation/Overwrite on Windows via
insufficient relative path sanitization

Package tar

Patched in >=4.4.18

Dependency of browserify-middleware [dev]

Path browserify-middleware > watchify > chokidar > fsevents >
node-pre-gyp > tar

More info https://github.com/advisories/GHSA-5955-9wpr-37jh


High Arbitrary File Creation/Overwrite via insufficient symlink
protection due to directory cache poisoning using symbolic
links

Package tar

Patched in >=4.4.18

Dependency of browserify-middleware [dev]

Path browserify-middleware > watchify > chokidar > fsevents >
node-pre-gyp > tar

More info https://github.com/advisories/GHSA-qq89-hq3f-393p


High Arbitrary File Creation/Overwrite via insufficient symlink
protection due to directory cache poisoning using symbolic
links

Package tar

Patched in >=4.4.16

Dependency of browserify-middleware [dev]

Path browserify-middleware > watchify > chokidar > fsevents >
node-pre-gyp > tar

More info https://github.com/advisories/GHSA-9r2w-394v-53qc


High Arbitrary File Creation/Overwrite due to insufficient
absolute path sanitization

Package tar

Patched in >=4.4.14

Dependency of browserify-middleware [dev]

Path browserify-middleware > watchify > chokidar > fsevents >
node-pre-gyp > tar

More info https://github.com/advisories/GHSA-3jfq-g458-7qm9


High Arbitrary File Creation/Overwrite via insufficient symlink
protection due to directory cache poisoning

Package tar

Patched in >=4.4.15

Dependency of browserify-middleware [dev]

Path browserify-middleware > watchify > chokidar > fsevents >
node-pre-gyp > tar

More info https://github.com/advisories/GHSA-r628-mhmh-qjhw


High Regular expression denial of service

Package glob-parent

Patched in >=5.1.2

Dependency of browserify-middleware [dev]

Path browserify-middleware > watchify > chokidar > glob-parent

More info https://github.com/advisories/GHSA-ww39-953v-wcq6


High Remote code execution via the `pretty` option.

Package pug-code-gen

Patched in >=2.0.3

Dependency of pug-cli

Path pug-cli > pug > pug-code-gen

More info https://github.com/advisories/GHSA-p493-635q-r6gr


High Remote code execution via the `pretty` option.

Package pug

Patched in >=3.0.1

Dependency of pug-cli

Path pug-cli > pug

More info https://github.com/advisories/GHSA-p493-635q-r6gr


High Prototype Pollution

Package ini

Patched in >=1.3.6

Dependency of browserify-middleware [dev]

Path browserify-middleware > watchify > chokidar > fsevents >
node-pre-gyp > rc > ini

More info https://github.com/advisories/GHSA-qqgx-2p2h-9c37


Moderate Prototype Pollution in minimist

Package minimist

Patched in >=1.2.3

Dependency of browserify-middleware [dev]

Path browserify-middleware > watchify > chokidar > fsevents >
node-pre-gyp > rc > minimist

More info https://github.com/advisories/GHSA-vh95-rmgr-6w4m


Moderate Prototype Pollution in minimist

Package minimist

Patched in >=0.2.1

Dependency of browserify-middleware [dev]

Path browserify-middleware > watchify > chokidar > fsevents >
node-pre-gyp > mkdirp > minimist

More info https://github.com/advisories/GHSA-vh95-rmgr-6w4m


Moderate Prototype Pollution in minimist

Package minimist

Patched in >=0.2.1

Dependency of browserify-middleware [dev]

Path browserify-middleware > watchify > chokidar > fsevents >
node-pre-gyp > tar > mkdirp > minimist

More info https://github.com/advisories/GHSA-vh95-rmgr-6w4m

found 49 vulnerabilities (12 moderate, 37 high) in 816 scanned packages
run `npm audit fix` to fix 37 of them.
12 vulnerabilities require manual review. See the full report for details.
After Running `npm audit fix`

root@d4c6842678e0:~/esplora# npm audit fix
npm WARN esplora@0.1.0 No repository field.
npm WARN optional SKIPPING OPTIONAL DEPENDENCY: fsevents@2.1.3 (node_modules/chokidar/node_modules/fsevents):
npm WARN notsup SKIPPING OPTIONAL DEPENDENCY: Unsupported platform for fsevents@2.1.3: wanted {"os":"darwin","arch":"any"} (current: {"os":"linux","arch":"ppc64"})
npm WARN optional SKIPPING OPTIONAL DEPENDENCY: fsevents@1.2.7 (node_modules/fsevents):
npm WARN notsup SKIPPING OPTIONAL DEPENDENCY: Unsupported platform for fsevents@1.2.7: wanted {"os":"darwin","arch":"any"} (current: {"os":"linux","arch":"ppc64"})

+ pug@3.0.2
added 5 packages from 4 contributors, removed 4 packages and updated 13 packages in 8.412s

34 packages are looking for funding
run `npm fund` for details

fixed 37 of 49 vulnerabilities in 816 scanned packages
12 vulnerabilities required manual review and could not be updated

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.