adobe / adobe/jsonschema2md

Multiple high vulnerabilities found during `npm audit`

Open
#368 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
JavaScript
Stars
724
Forks
150
Avg merge
18h 22m
Merged PRs (30d)
4

Description

### Expected Behaviour

No vulnerabilities found

### Actual Behaviour

Security vulnerabilities are found with:

- set-value
- ansi-html
- glob-parent

### Reproduce Scenario (including but not limited to)

#### Steps to Reproduce

Run npm audit

#### Platform and Version

6.1.4

#### Sample Code that illustrates the problem

#### Logs taken while reproducing problem

```
└──────────────────────────────────────────────────────────────────────────────┘
┌───────────────┬──────────────────────────────────────────────────────────────┐
│ High │ Prototype Pollution in set-value │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Package │ set-value │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Patched in │ >=4.0.1 │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Dependency of │ @adobe/jsonschema2md [dev] │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Path │ @adobe/jsonschema2md > ferrum > documentation > micromatch > │
│ │ snapdragon > base > cache-base > set-value │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-4jqc-8m5r-9rpr │
└───────────────┴──────────────────────────────────────────────────────────────┘
┌───────────────┬──────────────────────────────────────────────────────────────┐
│ High │ Prototype Pollution in set-value │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Package │ set-value │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Patched in │ >=4.0.1 │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Dependency of │ @adobe/jsonschema2md [dev] │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Path │ @adobe/jsonschema2md > ferrum > documentation > micromatch > │
│ │ braces > snapdragon > base > cache-base > set-value │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-4jqc-8m5r-9rpr │
└───────────────┴──────────────────────────────────────────────────────────────┘
┌───────────────┬──────────────────────────────────────────────────────────────┐
│ High │ Prototype Pollution in set-value │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Package │ set-value │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Patched in │ >=4.0.1 │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Dependency of │ @adobe/jsonschema2md [dev] │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Path │ @adobe/jsonschema2md > ferrum > documentation > micromatch > │
│ │ extglob > expand-brackets > snapdragon > base > cache-base > │
│ │ set-value │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-4jqc-8m5r-9rpr │
└───────────────┴──────────────────────────────────────────────────────────────┘
┌───────────────┬──────────────────────────────────────────────────────────────┐
│ High │ Prototype Pollution in set-value │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Package │ set-value │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Patched in │ >=4.0.1 │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Dependency of │ @adobe/jsonschema2md [dev] │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Path │ @adobe/jsonschema2md > ferrum > documentation > micromatch > │
│ │ snapdragon > base > cache-base > union-value > set-value │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-4jqc-8m5r-9rpr │
└───────────────┴──────────────────────────────────────────────────────────────┘
┌───────────────┬──────────────────────────────────────────────────────────────┐
│ High │ Prototype Pollution in set-value │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Package │ set-value │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Patched in │ >=4.0.1 │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Dependency of │ @adobe/jsonschema2md [dev] │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Path │ @adobe/jsonschema2md > ferrum > documentation > micromatch > │
│ │ braces > snapdragon > base > cache-base > union-value > │
│ │ set-value │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-4jqc-8m5r-9rpr │
└───────────────┴──────────────────────────────────────────────────────────────┘
┌───────────────┬──────────────────────────────────────────────────────────────┐
│ High │ Prototype Pollution in set-value │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Package │ set-value │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Patched in │ >=4.0.1 │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Dependency of │ @adobe/jsonschema2md [dev] │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Path │ @adobe/jsonschema2md > ferrum > documentation > micromatch > │
│ │ extglob > expand-brackets > snapdragon > base > cache-base > │
│ │ union-value > set-value │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-4jqc-8m5r-9rpr │
└───────────────┴──────────────────────────────────────────────────────────────┘
┌───────────────┬──────────────────────────────────────────────────────────────┐
│ High │ Uncontrolled Resource Consumption in ansi-html │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Package │ ansi-html │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Patched in │ No patch available │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Dependency of │ @adobe/jsonschema2md [dev] │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Path │ @adobe/jsonschema2md > ferrum > documentation > ansi-html │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-whgm-jr23-g3j9 │
└───────────────┴──────────────────────────────────────────────────────────────┘
┌───────────────┬──────────────────────────────────────────────────────────────┐
│ High │ Regular expression denial of service │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Package │ glob-parent │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Patched in │ >=5.1.2 │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Dependency of │ @adobe/jsonschema2md [dev] │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Path │ @adobe/jsonschema2md > ferrum > documentation > vinyl-fs > │
│ │ glob-stream > glob-parent │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-ww39-953v-wcq6 │

```

Contributor guide

Open the contributing guide

Research direction

Start by running npm audit for version 6.1.4 and trace the listed dependency paths from @adobe/jsonschema2md through ferrum and documentation. Check whether patched versions resolve set-value and glob-parent, then determine how the unpatched ansi-html vulnerability should be handled. Done means npm audit no longer reports these high vulnerabilities, or the remaining risk and mitigation are documented.

Written by the indexing model from the issue text.

Assessment

Tech stack
javascript
Domain
security, tooling
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.