Merge branch 'main' into VACMS-20190-some-zip-codes-crash-FL #82629
Annotations
10 errors
Audit dependencies
Security advisory:
Title: Unauthenticated Denial of Service in the octokit/webhooks library
Module name: octokit
Dependency: octokit
Path: octokit
Severity: high
Details: https://github.com/advisories/GHSA-pwfr-8pq7-x9qv
|
Audit dependencies
Security advisory:
Title: path-to-regexp outputs backtracking regular expressions
Module name: path-to-regexp
Dependency: express
Path: express>path-to-regexp
Severity: high
Details: https://github.com/advisories/GHSA-9wv6-86v2-598j
|
Audit dependencies
Security advisory:
Title: cookie accepts cookie name, path, and domain with out of bounds characters
Module name: cookie
Dependency: express
Path: express>cookie
Severity: low
Details: https://github.com/advisories/GHSA-pxg6-pf52-xh8x
|
Audit dependencies
Security advisory:
Title: send vulnerable to template injection that can lead to XSS
Module name: send
Dependency: express
Path: express>send
Severity: low
Details: https://github.com/advisories/GHSA-m6fv-jmcg-4jfg
|
Audit dependencies
Security advisory:
Title: serve-static vulnerable to template injection that can lead to XSS
Module name: serve-static
Dependency: express
Path: express>serve-static
Severity: low
Details: https://github.com/advisories/GHSA-cm22-4g7w-348p
|
Audit dependencies
Security advisory:
Title: Unpatched `path-to-regexp` ReDoS in 0.1.x
Module name: path-to-regexp
Dependency: express
Path: express>path-to-regexp
Severity: moderate
Details: https://github.com/advisories/GHSA-rhx6-c78j-4q9w
|
Audit dependencies
Security advisory:
Title: cookie accepts cookie name, path, and domain with out of bounds characters
Module name: cookie
Dependency: cookie
Path: cookie
Severity: low
Details: https://github.com/advisories/GHSA-pxg6-pf52-xh8x
|
Audit dependencies
Security advisory:
Title: cookie accepts cookie name, path, and domain with out of bounds characters
Module name: cookie
Dependency: local-storage-fallback
Path: local-storage-fallback>cookie
Severity: low
Details: https://github.com/advisories/GHSA-pxg6-pf52-xh8x
|
Audit dependencies
Security advisory:
Title: Express.js Open Redirect in malformed URLs
Module name: express
Dependency: express
Path: express
Severity: moderate
Details: https://github.com/advisories/GHSA-rv95-896h-c2vc
|
Audit dependencies
Security advisory:
Title: express vulnerable to XSS via response.redirect()
Module name: express
Dependency: express
Path: express
Severity: low
Details: https://github.com/advisories/GHSA-qw6h-vgh9-j6wx
|
Loading