vulnerability error
- Dominant language
- JavaScript
- Stars
- 39
- Forks
- 15
- PR merge metrics
- No merged PRs in 30d
Description
Hi, there are multiple vulnerabilities with some widely-used versions of your package.
Can they be addressed and back-ported?
```
npx: installed 115 in 9.19s
(+) 1 vulnerability found
┌────────────┬────────────────────────────────────────────────────────────────────┐
│ │ Memory Exposure │
├────────────┼────────────────────────────────────────────────────────────────────┤
│ Name │ tunnel-agent │
├────────────┼────────────────────────────────────────────────────────────────────┤
│ CVSS │ 5 (Medium) │
├────────────┼────────────────────────────────────────────────────────────────────┤
│ Installed │ 0.4.3 │
├────────────┼────────────────────────────────────────────────────────────────────┤
│ Vulnerable │ <0.6.0 │
├────────────┼────────────────────────────────────────────────────────────────────┤
│ Patched │ >=0.6.0 │
├────────────┼────────────────────────────────────────────────────────────────────┤
│ Path │ nuxt-imagemin@0.1.2 > imagemin-webpack-plugin@2.1.1 > │
│ │ imagemin-optipng@5.2.1 > optipng-bin@3.1.4 > bin-build@2.2.0 > │
│ │ download@4.4.3 > caw@1.2.0 > tunnel-agent@0.4.3 │
├────────────┼────────────────────────────────────────────────────────────────────┤
│ More Info │ https://nodesecurity.io/advisories/598 │
└────────────┴────────────────────────────────────────────────────────────────────┘
┌────────────┬────────────────────────────────────────────────────────────────────┐
│ │ Prototype Pollution │
├────────────┼────────────────────────────────────────────────────────────────────┤
│ Name │ deep-extend │
├────────────┼────────────────────────────────────────────────────────────────────┤
│ CVSS │ 2 (Low) │
├────────────┼────────────────────────────────────────────────────────────────────┤
│ Installed │ 0.5.1 │
├────────────┼────────────────────────────────────────────────────────────────────┤
│ Vulnerable │ <6.5.2 │
├────────────┼────────────────────────────────────────────────────────────────────┤
│ Patched │ >=6.5.2 │
├────────────┼────────────────────────────────────────────────────────────────────┤
│ Path │ wemake-vue-demo@0.1.0 > nuxt-imagemin@0.1.2 > │
│ │ imagemin-webpack-plugin@2.1.1 > imagemin-optipng@5.2.1 > │
│ │ optipng-bin@3.1.4 > bin-build@2.2.0 > download@4.4.3 > caw@1.2.0 > │
│ │ get-proxy@1.1.0 > rc@1.2.7 > deep-extend@0.5.1 │
├────────────┼────────────────────────────────────────────────────────────────────┤
│ More Info │ https://nodesecurity.io/advisories/594 │
└────────────┴────────────────────────────────────────────────────────────────────┘
┌────────────┬────────────────────────────────────────────────────────────────────┐
│ │ Prototype Pollution │
├────────────┼────────────────────────────────────────────────────────────────────┤
│ Name │ deep-extend │
├────────────┼────────────────────────────────────────────────────────────────────┤
│ CVSS │ 2 (Low) │
├────────────┼────────────────────────────────────────────────────────────────────┤
│ Installed │ 0.5.1 │
├────────────┼────────────────────────────────────────────────────────────────────┤
│ Vulnerable │ All │
├────────────┼────────────────────────────────────────────────────────────────────┤
│ Patched │ None ���
├────────────┼────────────────────────────────────────────────────────────────────┤
│ Path │ wemake-vue-demo@0.1.0 > nuxt-imagemin@0.1.2 > │
│ │ imagemin-webpack-plugin@2.1.1 > imagemin-optipng@5.2.1 > │
│ │ optipng-bin@3.1.4 > bin-build@2.2.0 > download@4.4.3 > caw@1.2.0 > │
│ │ get-proxy@1.1.0 > rc@1.2.7 > deep-extend@0.5.1 │
├────────────┼────────────────────────────────────────────────────────────────────┤
│ More Info │ https://nodesecurity.io/advisories/612 │
└────────────┴────────────────────────────────────────────────────────────────────┘
┌────────────┬────────────────────────────────────────────────────────────────────┐
│ │ Prototype Pollution │
├────────────┼────────────────────────────────────────────────────────────────────┤
│ Name │ deep-extend │
├────────────┼────────────────────────────────────────────────────────────────────┤
│ CVSS │ 2 (Low) │
├────────────┼────────────────────────────────────────────────────────────────────┤
│ Installed │ 0.5.1 │
├────────────┼────────────────────────────────────────────────────────────────────┤
│ Vulnerable │ <1.0.1 │
├────────────┼────────────────────────────────────────────────────────────────────┤
│ Patched │ >=1.0.1 │
├────────────┼────────────────────────────────────────────────────────────────────┤
│ Path │ wemake-vue-demo@0.1.0 > nuxt-imagemin@0.1.2 > │
│ │ imagemin-webpack-plugin@2.1.1 > imagemin-optipng@5.2.1 > │
│ │ optipng-bin@3.1.4 > bin-build@2.2.0 > download@4.4.3 > caw@1.2.0 > │
│ │ get-proxy@1.1.0 > rc@1.2.7 > deep-extend@0.5.1 │
├────────────┼────────────────────────────────────────────────────────────────────┤
│ More Info │ https://nodesecurity.io/advisories/611 │
└────────────┴─���──────────────────────────────────────────────────────────────────┘
┌────────────┬────────────────────────────────────────────────────────────────────┐
│ │ Memory Exposure │
├────────────┼────────────────────────────────────────────────────────────────────┤
│ Name │ tunnel-agent │
├────────────┼────────────────────────────────────────────────────────────────────┤
│ CVSS │ 5 (Medium) │
├────────────┼────────────────────────────────────────────────────────────────────┤
│ Installed │ 0.4.3 │
├─────���──────┼────────────────────────────────────────────────────────────────────┤
│ Vulnerable │ <0.6.0 │
├────────────┼────────────────────────────────────────────────────────────────────┤
│ Patched │ >=0.6.0 │
├────────────┼────────────────────────────────────────────────────────────────────┤
│ Path │ wemake-vue-demo@0.1.0 > nuxt-imagemin@0.1.2 > │
│ │ imagemin-webpack-plugin@2.1.1 > imagemin-optipng@5.2.1 > │
│ │ optipng-bin@3.1.4 > bin-build@2.2.0 > download@4.4.3 > caw@1.2.0 > │
│ │ tunnel-agent@0.4.3 │
├────────────┼───────────────────────────���────────────────────────────────────────┤
│ More Info │ https://nodesecurity.io/advisories/598 │
└────────────┴────────────────────────────────────────────────────────────────────┘
```
Related: https://github.com/wemake-services/nuxt-imagemin/issues/2
Related: https://github.com/Klathmon/imagemin-webpack-plugin/issues/60
Related: https://github.com/imagemin/optipng-bin/issues/98
Contributor guide
No contributing guide indexed for this repository
Research direction
No source files or tests are mentioned. Start by tracing the listed dependency paths for tunnel-agent and deep-extend, then determine how the reported versions are selected and whether patched versions can be used. Done means the reported vulnerabilities are addressed and the dependency scan no longer flags these paths.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- javascript, nodejs
- Domain
- build-system, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100