Dependabot (critical/High) - forms-flow-web
@antsand is already working on this.
Since Dec 6, 2023.
- Dominant language
- Python
- Stars
- 8
- Forks
- 2
- Avg merge
- 14h 34m
- Merged PRs (30d)
- 46
Description
Dependabot link - https://github.com/bcgov/foi-flow/security/dependabot?q=is%3Aopen+manifest%3Aforms-flow-web%2Fpackage-lock.json
Upgrade to latest version of Nodejs before addressing these
- [x] - crypto-js PBKDF2 1,000 times weaker than specified in 1993 and 1.3M times weaker than current standard
- [x] - Babel vulnerable to arbitrary code execution when compiling specifically crafted malicious code
- [x] - Cross-realm object access in Webpack 5
- [x] - Insufficient validation when decoding a Socket.IO packet
- [x] - ReDoS Vulnerability in ua-parser-js version
- [x] - minimatch ReDoS vulnerability
- [x] - Prototype Pollution in JSON5 via Parse Method
- [x] - decode-uri-component vulnerable to Denial of Service (DoS)
- [x] - Terser insecure use of regular expressions leads to ReDoS
- [x] - Moment.js vulnerable to Inefficient Regular Expression Complexity
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Assessment
This issue has not been assessed yet.