bcgov / bcgov/foi-flow

Dependabot (critical/High) - forms-flow-web

Open
#4,777 2 comments 0 reactions 1 assignee View on GitHub

@antsand is already working on this.

Since Dec 6, 2023.

dependency marshal security Tech Debt
Dominant language
Python
Stars
8
Forks
2
Avg merge
14h 34m
Merged PRs (30d)
46

Description

Dependabot link - https://github.com/bcgov/foi-flow/security/dependabot?q=is%3Aopen+manifest%3Aforms-flow-web%2Fpackage-lock.json

Upgrade to latest version of Nodejs before addressing these

- [x] - crypto-js PBKDF2 1,000 times weaker than specified in 1993 and 1.3M times weaker than current standard
- [x] - Babel vulnerable to arbitrary code execution when compiling specifically crafted malicious code
- [x] - Cross-realm object access in Webpack 5
- [x] - Insufficient validation when decoding a Socket.IO packet
- [x] - ReDoS Vulnerability in ua-parser-js version
- [x] - minimatch ReDoS vulnerability
- [x] - Prototype Pollution in JSON5 via Parse Method
- [x] - decode-uri-component vulnerable to Denial of Service (DoS)
- [x] - Terser insecure use of regular expressions leads to ReDoS
- [x] - Moment.js vulnerable to Inefficient Regular Expression Complexity

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.