Multiple high vulnerabilities found during `npm audit`
- Dominant language
- JavaScript
- Stars
- 724
- Forks
- 150
- Avg merge
- 18h 22m
- Merged PRs (30d)
- 4
Description
### Expected Behaviour
No vulnerabilities found
### Actual Behaviour
Security vulnerabilities are found with:
- set-value
- ansi-html
- glob-parent
### Reproduce Scenario (including but not limited to)
#### Steps to Reproduce
Run npm audit
#### Platform and Version
6.1.4
#### Sample Code that illustrates the problem
#### Logs taken while reproducing problem
```
└──────────────────────────────────────────────────────────────────────────────┘
┌───────────────┬──────────────────────────────────────────────────────────────┐
│ High │ Prototype Pollution in set-value │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Package │ set-value │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Patched in │ >=4.0.1 │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Dependency of │ @adobe/jsonschema2md [dev] │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Path │ @adobe/jsonschema2md > ferrum > documentation > micromatch > │
│ │ snapdragon > base > cache-base > set-value │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-4jqc-8m5r-9rpr │
└───────────────┴──────────────────────────────────────────────────────────────┘
┌───────────────┬──────────────────────────────────────────────────────────────┐
│ High │ Prototype Pollution in set-value │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Package │ set-value │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Patched in │ >=4.0.1 │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Dependency of │ @adobe/jsonschema2md [dev] │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Path │ @adobe/jsonschema2md > ferrum > documentation > micromatch > │
│ │ braces > snapdragon > base > cache-base > set-value │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-4jqc-8m5r-9rpr │
└───────────────┴──────────────────────────────────────────────────────────────┘
┌───────────────┬──────────────────────────────────────────────────────────────┐
│ High │ Prototype Pollution in set-value │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Package │ set-value │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Patched in │ >=4.0.1 │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Dependency of │ @adobe/jsonschema2md [dev] │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Path │ @adobe/jsonschema2md > ferrum > documentation > micromatch > │
│ │ extglob > expand-brackets > snapdragon > base > cache-base > │
│ │ set-value │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-4jqc-8m5r-9rpr │
└───────────────┴──────────────────────────────────────────────────────────────┘
┌───────────────┬──────────────────────────────────────────────────────────────┐
│ High │ Prototype Pollution in set-value │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Package │ set-value │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Patched in │ >=4.0.1 │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Dependency of │ @adobe/jsonschema2md [dev] │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Path │ @adobe/jsonschema2md > ferrum > documentation > micromatch > │
│ │ snapdragon > base > cache-base > union-value > set-value │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-4jqc-8m5r-9rpr │
└───────────────┴──────────────────────────────────────────────────────────────┘
┌───────────────┬──────────────────────────────────────────────────────────────┐
│ High │ Prototype Pollution in set-value │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Package │ set-value │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Patched in │ >=4.0.1 │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Dependency of │ @adobe/jsonschema2md [dev] │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Path │ @adobe/jsonschema2md > ferrum > documentation > micromatch > │
│ │ braces > snapdragon > base > cache-base > union-value > │
│ │ set-value │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-4jqc-8m5r-9rpr │
└───────────────┴──────────────────────────────────────────────────────────────┘
┌───────────────┬──────────────────────────────────────────────────────────────┐
│ High │ Prototype Pollution in set-value │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Package │ set-value │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Patched in │ >=4.0.1 │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Dependency of │ @adobe/jsonschema2md [dev] │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Path │ @adobe/jsonschema2md > ferrum > documentation > micromatch > │
│ │ extglob > expand-brackets > snapdragon > base > cache-base > │
│ │ union-value > set-value │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-4jqc-8m5r-9rpr │
└───────────────┴──────────────────────────────────────────────────────────────┘
┌───────────────┬──────────────────────────────────────────────────────────────┐
│ High │ Uncontrolled Resource Consumption in ansi-html │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Package │ ansi-html │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Patched in │ No patch available │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Dependency of │ @adobe/jsonschema2md [dev] │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Path │ @adobe/jsonschema2md > ferrum > documentation > ansi-html │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-whgm-jr23-g3j9 │
└───────────────┴──────────────────────────────────────────────────────────────┘
┌───────────────┬──────────────────────────────────────────────────────────────┐
│ High │ Regular expression denial of service │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Package │ glob-parent │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Patched in │ >=5.1.2 │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Dependency of │ @adobe/jsonschema2md [dev] │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Path │ @adobe/jsonschema2md > ferrum > documentation > vinyl-fs > │
│ │ glob-stream > glob-parent │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ More info │ https://github.com/advisories/GHSA-ww39-953v-wcq6 │
```
Contributor guide
Research direction
Start by running npm audit for version 6.1.4 and trace the listed dependency paths from @adobe/jsonschema2md through ferrum and documentation. Check whether patched versions resolve set-value and glob-parent, then determine how the unpatched ansi-html vulnerability should be handled. Done means npm audit no longer reports these high vulnerabilities, or the remaining risk and mitigation are documented.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- javascript
- Domain
- security, tooling
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100