assemblee-virtuelle / assemblee-virtuelle/Semantic-Bus

Dependency security issues

Open
#296 0 comments 0 reactions 0 assignees View on GitHub
dependencies R&D
Dominant language
JavaScript
Stars
57
Forks
10
Avg merge
8m
Merged PRs (30d)
55

Description

We have to update or remove the dependancies that are on a high or critical level of alert in the [dependabot alerts section of the repository](https://github.com/assemblee-virtuelle/Semantic-Bus/security/dependabot).

## Critical 🟥 🟥

Prototype pollution
- flat
- webpack loader-utils

- Mongoose : Improper Input Validation in Automattic
- xmldom : multiple root nodes in a DOM

## High 🟥

Prototype pollution
- JSON5 (parse)
- qs

- Dicer : crash in headerparser
- ReDoS : minimatch vulnerability + Regular Expression Denial of Service
- jsonwebtoken : insecure input validation : jwt.verify
- node-forge : Improper Verification of Cryptographic Signature
- node-fetch : Exposure of Sensitive Information to an Unauthorized Actor
- ssh2 : OS Command Injection

## Moderate 🟧

- jsonwebtoken :
- vulnerable to signature validation bypass due to insecure default algorithm in jwt.verify()
- insecure implementation of key retrieval function could lead to Forgeable Public/Private Tokens from RSA to HMAC
- unrestricted key type could lead to legacy keys usage
- Passport : before 0.6.0 vulnerable to session regeneration when a users logs in or out
- Got : redirect to a UNIX socket
- cross-fetch : incorrect authorization
- node-forge : open redirect
- xmldom : Misinterpretation of malicious XML input
- validator.js : Inefficient Regular Expression Complexity
- SheetJs Pro : denial of service
- bcrypt : Integer Overflow or Wraparound and Use of a Broken or Risky Cryptographic Algorithm

## Low 🟨

- decode-uri-component : vulnerable to Denial of Service (DoS)
- semver-regex : Regular expression denial of service
- node-forge : prototype pollution in debug api + url parsing (undesired behavior)

Contributor guide

No contributing guide indexed for this repository

Research direction

Start with the repository's Dependabot alerts section and compare the listed high and critical vulnerabilities with the current dependency state. Identify which dependencies can be updated or removed, then verify that the listed high and critical alerts are resolved; the issue does not name specific files or tests.

Written by the indexing model from the issue text.

Assessment

Tech stack
javascript
Domain
security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.