[Snyk] Security upgrade puppeteer from 1.11.0 to 18.2.0 #300
Security Report
You have successfully remediated 127 vulnerabilities, but introduced 62 new vulnerabilities in this branch.
❌ New vulnerabilities:
Partial results (57 vulnerabilities) are displayed below due to a content size limitation in GitHub. To view information on the remaining vulnerabilities, navigate to the Mend Application.
CVE | Severity | CVSS Score | Vulnerable Library | Suggested Fix | Issue |
---|---|---|---|---|---|
MSC-2023-16609Path to dependency file: /fixtures/flight/package.json Path to vulnerable library: /fixtures/flight/package.json Dependency Hierarchy: -> react-dev-utils-9.1.0.tgz (Root Library) -> fork-ts-checker-webpack-plugin-1.5.0.tgz -> chokidar-2.1.8.tgz -> ❌ fsevents-1.2.9.tgz (Vulnerable Library) |
Critical | 9.8 | fsevents-1.2.9.tgz | None | |
MSC-2023-16606Path to dependency file: /fixtures/packaging/webpack-alias/dev/package.json Path to vulnerable library: /fixtures/packaging/webpack-alias/dev/package.json,/fixtures/packaging/webpack/prod/package.json,/fixtures/packaging/webpack-alias/prod/package.json,/fixtures/packaging/webpack/dev/package.json,/fixtures/attribute-behavior/package.json,/fixtures/expiration/package.json Dependency Hierarchy: -> webpack-1.15.0.tgz (Root Library) -> watchpack-0.2.9.tgz -> chokidar-1.7.0.tgz -> ❌ fsevents-1.1.2.tgz (Vulnerable Library) |
Critical | 9.8 | fsevents-1.1.2.tgz | None | |
MSC-2023-16604Path to dependency file: /fixtures/expiration/package.json Path to vulnerable library: /fixtures/expiration/package.json,/fixtures/concurrent/time-slicing/package.json Dependency Hierarchy: -> react-scripts-1.1.4.tgz (Root Library) -> webpack-dev-server-2.9.4.tgz -> chokidar-1.7.0.tgz -> ❌ fsevents-1.1.3.tgz (Vulnerable Library) |
Critical | 9.8 | fsevents-1.1.3.tgz | None | |
MSC-2023-16600Path to dependency file: /fixtures/flight/package.json Path to vulnerable library: /fixtures/flight/package.json,/fixtures/concurrent/time-slicing/package.json Dependency Hierarchy: -> react-scripts-1.1.4.tgz (Root Library) -> ❌ fsevents-1.2.4.tgz (Vulnerable Library) |
Critical | 9.8 | fsevents-1.2.4.tgz | None | |
CVE-2023-45311Path to dependency file: /fixtures/flight/package.json Path to vulnerable library: /fixtures/flight/package.json Dependency Hierarchy: -> react-dev-utils-9.1.0.tgz (Root Library) -> fork-ts-checker-webpack-plugin-1.5.0.tgz -> chokidar-2.1.8.tgz -> ❌ fsevents-1.2.9.tgz (Vulnerable Library) |
Critical | 9.8 | fsevents-1.2.9.tgz | Upgrade to version: fsevents - 1.2.11 | None |
CVE-2023-45311Path to dependency file: /fixtures/flight/package.json Path to vulnerable library: /fixtures/flight/package.json,/fixtures/concurrent/time-slicing/package.json Dependency Hierarchy: -> react-scripts-1.1.4.tgz (Root Library) -> ❌ fsevents-1.2.4.tgz (Vulnerable Library) |
Critical | 9.8 | fsevents-1.2.4.tgz | Upgrade to version: fsevents - 1.2.11 | None |
CVE-2023-45311Path to dependency file: /fixtures/expiration/package.json Path to vulnerable library: /fixtures/expiration/package.json,/fixtures/concurrent/time-slicing/package.json Dependency Hierarchy: -> react-scripts-1.1.4.tgz (Root Library) -> webpack-dev-server-2.9.4.tgz -> chokidar-1.7.0.tgz -> ❌ fsevents-1.1.3.tgz (Vulnerable Library) |
Critical | 9.8 | fsevents-1.1.3.tgz | Upgrade to version: fsevents - 1.2.11 | None |
CVE-2023-26136Path to dependency file: /fixtures/attribute-behavior/package.json Path to vulnerable library: /fixtures/attribute-behavior/package.json,/scripts/bench/package.json Dependency Hierarchy: -> react-scripts-1.0.11.tgz (Root Library) -> fsevents-1.1.2.tgz -> node-pre-gyp-0.6.36.tgz -> request-2.81.0.tgz -> ❌ tough-cookie-2.3.2.tgz (Vulnerable Library) |
Critical | 9.8 | tough-cookie-2.3.2.tgz | Upgrade to version: tough-cookie - 4.1.3 | None |
CVE-2023-26136Path to dependency file: /fixtures/concurrent/time-slicing/package.json Path to vulnerable library: /fixtures/concurrent/time-slicing/package.json,/fixtures/packaging/webpack/dev/package.json,/fixtures/packaging/webpack-alias/dev/package.json,/fixtures/packaging/webpack/prod/package.json,/scripts/release/package.json,/fixtures/packaging/webpack-alias/prod/package.json,/fixtures/expiration/package.json Dependency Hierarchy: -> request-promise-json-1.0.4.tgz (Root Library) -> request-2.83.0.tgz -> ❌ tough-cookie-2.3.3.tgz (Vulnerable Library) |
Critical | 9.8 | tough-cookie-2.3.3.tgz | Upgrade to version: tough-cookie - 4.1.3 | None |
CVE-2023-26136Dependency Hierarchy: -> json-server-0.16.1.tgz (Root Library) -> request-2.88.2.tgz -> ❌ tough-cookie-2.5.0.tgz (Vulnerable Library) |
Critical | 9.8 | tough-cookie-2.5.0.tgz | Upgrade to version: tough-cookie - 4.1.3 | None |
CVE-2023-26136Path to dependency file: /package.json Path to vulnerable library: /package.json,/fixtures/flight/package.json Dependency Hierarchy: -> jest-24.9.0.tgz (Root Library) -> jest-cli-24.9.0.tgz -> jest-config-24.9.0.tgz -> jest-environment-jsdom-24.9.0.tgz -> jsdom-11.12.0.tgz -> ❌ tough-cookie-2.4.3.tgz (Vulnerable Library) |
Critical | 9.8 | tough-cookie-2.4.3.tgz | Upgrade to version: tough-cookie - 4.1.3 | None |
CVE-2022-0691Path to dependency file: /fixtures/flight/package.json Path to vulnerable library: /fixtures/flight/package.json Dependency Hierarchy: -> react-dev-utils-9.1.0.tgz (Root Library) -> sockjs-client-1.4.0.tgz -> ❌ url-parse-1.4.3.tgz (Vulnerable Library) |
Critical | 9.8 | url-parse-1.4.3.tgz | Upgrade to version: url-parse - 1.5.9 | #268 |
CVE-2022-0691Path to dependency file: /fixtures/blocks/package.json Path to vulnerable library: /fixtures/blocks/package.json Dependency Hierarchy: -> react-scripts-3.4.1.tgz (Root Library) -> webpack-dev-server-3.10.3.tgz -> sockjs-client-1.4.0.tgz -> ❌ url-parse-1.4.7.tgz (Vulnerable Library) |
Critical | 9.8 | url-parse-1.4.7.tgz | Upgrade to version: url-parse - 1.5.9 | #268 |
CVE-2021-44906Path to dependency file: /fixtures/packaging/webpack/dev/package.json Path to vulnerable library: /fixtures/packaging/webpack/dev/package.json,/fixtures/packaging/webpack-alias/dev/package.json,/scripts/bench/package.json,/fixtures/concurrent/time-slicing/package.json,/package.json,/fixtures/packaging/webpack-alias/prod/package.json,/fixtures/eslint/package.json,/fixtures/attribute-behavior/package.json,/fixtures/expiration/package.json,/fixtures/packaging/systemjs-builder/prod/package.json,/fixtures/flight/package.json,/fixtures/blocks/package.json,/fixtures/packaging/webpack/prod/package.json,/fixtures/packaging/systemjs-builder/dev/package.json Dependency Hierarchy: -> systemjs-builder-0.15.36.tgz (Root Library) -> mkdirp-0.5.1.tgz -> ❌ minimist-0.0.8.tgz (Vulnerable Library) |
Critical | 9.8 | minimist-0.0.8.tgz | Upgrade to version: minimist - 0.2.4,1.2.6 | #264 |
CVE-2021-44906Path to dependency file: /fixtures/packaging/webpack/prod/package.json Path to vulnerable library: /fixtures/packaging/webpack/prod/package.json,/fixtures/packaging/webpack-alias/dev/package.json,/fixtures/flight/package.json,/scripts/bench/package.json,/fixtures/packaging/webpack-alias/prod/package.json,/fixtures/attribute-behavior/package.json,/fixtures/expiration/package.json,/fixtures/concurrent/time-slicing/package.json,/fixtures/packaging/webpack/dev/package.json Dependency Hierarchy: -> jest-24.9.0.tgz (Root Library) -> jest-cli-24.9.0.tgz -> core-24.9.0.tgz -> reporters-24.9.0.tgz -> istanbul-reports-2.2.6.tgz -> handlebars-4.5.1.tgz -> optimist-0.6.1.tgz -> ❌ minimist-0.0.10.tgz (Vulnerable Library) |
Critical | 9.8 | minimist-0.0.10.tgz | Upgrade to version: minimist - 0.2.4,1.2.6 | #264 |
CVE-2021-44906Path to dependency file: /fixtures/expiration/package.json Path to vulnerable library: /fixtures/expiration/package.json,/fixtures/packaging/webpack-alias/prod/package.json,/fixtures/concurrent/time-slicing/package.json,/fixtures/packaging/browserify/dev/package.json,/fixtures/attribute-behavior/package.json,/fixtures/packaging/browserify/prod/package.json,/fixtures/packaging/webpack/dev/package.json,/fixtures/packaging/webpack-alias/dev/package.json,/fixtures/flight/package.json,/fixtures/packaging/webpack/prod/package.json Dependency Hierarchy: -> core-7.6.0.tgz (Root Library) -> json5-2.1.1.tgz -> ❌ minimist-1.2.0.tgz (Vulnerable Library) |
Critical | 9.8 | minimist-1.2.0.tgz | Upgrade to version: minimist - 0.2.4,1.2.6 | #264 |
CVE-2021-4279Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> react-devtools-extensions-0.0.0.tgz (Root Library) -> web-ext-4.3.0.tgz -> addons-linter-1.26.0.tgz -> ajv-merge-patch-4.1.0.tgz -> ❌ fast-json-patch-2.2.1.tgz (Vulnerable Library) |
Critical | 9.8 | fast-json-patch-2.2.1.tgz | Upgrade to version: fast-json-patch - 3.1.1 | None |
CVE-2021-23518Path to dependency file: /fixtures/packaging/browserify/dev/package.json Path to vulnerable library: /fixtures/packaging/browserify/dev/package.json,/fixtures/packaging/browserify/prod/package.json Dependency Hierarchy: -> browserify-13.3.0.tgz (Root Library) -> ❌ cached-path-relative-1.0.1.tgz (Vulnerable Library) |
Critical | 9.8 | cached-path-relative-1.0.1.tgz | Upgrade to version: cached-path-relative - 1.1.0 | None |
CVE-2020-7677Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> react-devtools-extensions-0.0.0.tgz (Root Library) -> web-ext-4.3.0.tgz -> mz-2.7.0.tgz -> thenify-all-1.6.0.tgz -> ❌ thenify-3.3.0.tgz (Vulnerable Library) |
Critical | 9.8 | thenify-3.3.0.tgz | Upgrade to version: thenify - 3.3.1;org.webjars.npm:thenify:3.3.1 | None |
CVE-2023-45133Path to dependency file: /fixtures/flight/package.json Path to vulnerable library: /fixtures/flight/package.json Dependency Hierarchy: -> jest-24.9.0.tgz (Root Library) -> jest-cli-24.9.0.tgz -> jest-config-24.9.0.tgz -> jest-jasmine2-24.9.0.tgz -> ❌ traverse-7.1.0.tgz (Vulnerable Library) |
High | 8.8 | traverse-7.1.0.tgz | Upgrade to version: @babel/traverse - 7.23.2 | None |
CVE-2023-45133Path to dependency file: /fixtures/blocks/package.json Path to vulnerable library: /fixtures/blocks/package.json Dependency Hierarchy: -> react-scripts-3.4.1.tgz (Root Library) -> babel-eslint-10.1.0.tgz -> ❌ traverse-7.9.0.tgz (Vulnerable Library) |
High | 8.8 | traverse-7.9.0.tgz | Upgrade to version: @babel/traverse - 7.23.2 | None |
CVE-2023-45133Path to dependency file: /fixtures/packaging/systemjs-builder/prod/package.json Path to vulnerable library: /fixtures/packaging/systemjs-builder/prod/package.json,/fixtures/expiration/package.json,/fixtures/concurrent/time-slicing/package.json,/fixtures/attribute-behavior/package.json,/fixtures/packaging/systemjs-builder/dev/package.json Dependency Hierarchy: -> systemjs-builder-0.15.36.tgz (Root Library) -> babel-core-6.26.0.tgz -> ❌ babel-traverse-6.26.0.tgz (Vulnerable Library) |
High | 8.8 | babel-traverse-6.26.0.tgz | Upgrade to version: @babel/traverse - 7.23.2 | None |
CVE-2023-45133Path to dependency file: /fixtures/flight/package.json Path to vulnerable library: /fixtures/flight/package.json Dependency Hierarchy: -> core-7.6.0.tgz (Root Library) -> ❌ traverse-7.7.2.tgz (Vulnerable Library) |
High | 8.8 | traverse-7.7.2.tgz | Upgrade to version: @babel/traverse - 7.23.2 | None |
CVE-2021-43138Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> react-devtools-extensions-0.0.0.tgz (Root Library) -> web-ext-4.3.0.tgz -> addons-linter-1.26.0.tgz -> dispensary-0.51.2.tgz -> ❌ async-3.2.0.tgz (Vulnerable Library) |
High | 7.8 | async-3.2.0.tgz | Upgrade to version: async - 2.6.4,3.2.2 | #197 |
CVE-2023-26115Path to dependency file: /package.json Path to vulnerable library: /package.json,/fixtures/blocks/package.json Dependency Hierarchy: -> react-devtools-extensions-0.0.0.tgz (Root Library) -> web-ext-4.3.0.tgz -> addons-linter-1.26.0.tgz -> eslint-5.16.0.tgz -> optionator-0.8.3.tgz -> ❌ word-wrap-1.2.3.tgz (Vulnerable Library) |
High | 7.5 | word-wrap-1.2.3.tgz | Upgrade to version: word-wrap - 1.2.4 | None |
CVE-2022-37603Dependency Hierarchy: -> react-dev-utils-9.1.0.tgz (Root Library) -> ❌ loader-utils-1.2.3.tgz (Vulnerable Library) |
High | 7.5 | loader-utils-1.2.3.tgz | Upgrade to version: loader-utils - 1.4.2,2.0.4,3.2.1 | #240 |
CVE-2022-37603Path to dependency file: /fixtures/blocks/package.json Path to vulnerable library: /fixtures/blocks/package.json Dependency Hierarchy: -> react-scripts-3.4.1.tgz (Root Library) -> css-loader-3.4.2.tgz -> ❌ loader-utils-1.4.0.tgz (Vulnerable Library) |
High | 7.5 | loader-utils-1.4.0.tgz | Upgrade to version: loader-utils - 1.4.2,2.0.4,3.2.1 | #240 |
CVE-2022-31129Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> react-devtools-extensions-0.0.0.tgz (Root Library) -> web-ext-4.3.0.tgz -> bunyan-1.8.12.tgz -> ❌ moment-2.24.0.tgz (Vulnerable Library) |
High | 7.5 | moment-2.24.0.tgz | Upgrade to version: moment - 2.29.4 | #221 |
CVE-2022-25883Path to dependency file: /fixtures/dom/package.json Path to vulnerable library: /fixtures/dom/package.json Dependency Hierarchy: -> ❌ semver-5.5.0.tgz (Vulnerable Library) |
High | 7.5 | semver-5.5.0.tgz | Upgrade to version: semver - 5.7.2,6.3.1,7.5.2;org.webjars.npm:semver:7.5.2 | None |
CVE-2022-25883Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> react-devtools-extensions-0.0.0.tgz (Root Library) -> web-ext-4.3.0.tgz -> addons-linter-1.26.0.tgz -> ❌ semver-7.3.2.tgz (Vulnerable Library) |
High | 7.5 | semver-7.3.2.tgz | Upgrade to version: semver - 5.7.2,6.3.1,7.5.2;org.webjars.npm:semver:7.5.2 | None |
CVE-2022-25883Path to dependency file: /fixtures/packaging/webpack/prod/package.json Path to vulnerable library: /fixtures/packaging/webpack/prod/package.json,/fixtures/packaging/webpack-alias/dev/package.json,/scripts/release/package.json,/scripts/bench/package.json,/fixtures/packaging/webpack-alias/prod/package.json,/fixtures/packaging/webpack/dev/package.json,/fixtures/attribute-behavior/package.json,/fixtures/expiration/package.json,/fixtures/concurrent/time-slicing/package.json Dependency Hierarchy: -> ❌ semver-5.4.1.tgz (Vulnerable Library) |
High | 7.5 | semver-5.4.1.tgz | Upgrade to version: semver - 5.7.2,6.3.1,7.5.2;org.webjars.npm:semver:7.5.2 | None |
CVE-2022-25883Path to dependency file: /fixtures/packaging/systemjs-builder/prod/package.json Path to vulnerable library: /fixtures/packaging/systemjs-builder/prod/package.json,/fixtures/packaging/systemjs-builder/dev/package.json Dependency Hierarchy: -> systemjs-builder-0.15.36.tgz (Root Library) -> traceur-0.0.105.tgz -> ❌ semver-4.3.6.tgz (Vulnerable Library) |
High | 7.5 | semver-4.3.6.tgz | Upgrade to version: semver - 5.7.2,6.3.1,7.5.2;org.webjars.npm:semver:7.5.2 | None |
CVE-2022-25883Path to dependency file: /package.json Path to vulnerable library: /package.json,/fixtures/flight/package.json,/fixtures/blocks/package.json Dependency Hierarchy: -> react-devtools-extensions-0.0.0.tgz (Root Library) -> web-ext-4.3.0.tgz -> sign-addon-2.0.5.tgz -> jsonwebtoken-8.5.1.tgz -> ❌ semver-5.7.1.tgz (Vulnerable Library) |
High | 7.5 | semver-5.7.1.tgz | Upgrade to version: semver - 5.7.2,6.3.1,7.5.2;org.webjars.npm:semver:7.5.2 | None |
CVE-2022-25883Path to dependency file: /scripts/bench/package.json Path to vulnerable library: /scripts/bench/package.json Dependency Hierarchy: -> nodegit-0.18.3.tgz (Root Library) -> node-gyp-3.6.2.tgz -> ❌ semver-5.3.0.tgz (Vulnerable Library) |
High | 7.5 | semver-5.3.0.tgz | Upgrade to version: semver - 5.7.2,6.3.1,7.5.2;org.webjars.npm:semver:7.5.2 | None |
CVE-2022-25883Path to dependency file: /fixtures/flight/package.json Path to vulnerable library: /fixtures/flight/package.json Dependency Hierarchy: -> core-7.6.0.tgz (Root Library) -> ❌ semver-5.5.1.tgz (Vulnerable Library) |
High | 7.5 | semver-5.5.1.tgz | Upgrade to version: semver - 5.7.2,6.3.1,7.5.2;org.webjars.npm:semver:7.5.2 | None |
CVE-2022-25883Path to dependency file: /fixtures/nesting/package.json Path to vulnerable library: /fixtures/nesting/node_modules/react-scripts/node_modules/semver/package.json,/package.json,/fixtures/blocks/package.json,/fixtures/flight/package.json Dependency Hierarchy: -> ❌ semver-6.3.0.tgz (Vulnerable Library) |
High | 7.5 | semver-6.3.0.tgz | Upgrade to version: semver - 5.7.2,6.3.1,7.5.2;org.webjars.npm:semver:7.5.2 | None |
CVE-2022-25883Dependency Hierarchy: -> react-scripts-3.4.1.tgz (Root Library) -> babel-preset-react-app-9.1.2.tgz -> preset-env-7.9.0.tgz -> core-js-compat-3.6.4.tgz -> ❌ semver-7.0.0.tgz (Vulnerable Library) |
High | 7.5 | semver-7.0.0.tgz | Upgrade to version: semver - 5.7.2,6.3.1,7.5.2;org.webjars.npm:semver:7.5.2 | None |
CVE-2022-24999Path to dependency file: /fixtures/blocks/package.json Path to vulnerable library: /fixtures/blocks/package.json,/fixtures/flight/package.json Dependency Hierarchy: -> json-server-0.16.1.tgz (Root Library) -> body-parser-1.19.0.tgz -> ❌ qs-6.7.0.tgz (Vulnerable Library) |
High | 7.5 | qs-6.7.0.tgz | Upgrade to version: qs - 6.2.4,6.3.3,6.4.1,6.5.3,6.6.1,6.7.3,6.8.3,6.9.7,6.10.3 | #267 |
CVE-2022-24999Path to dependency file: /fixtures/blocks/package.json Path to vulnerable library: /fixtures/blocks/package.json,/fixtures/flight/package.json,/package.json Dependency Hierarchy: -> react-devtools-extensions-0.0.0.tgz (Root Library) -> web-ext-4.3.0.tgz -> sign-addon-2.0.5.tgz -> request-2.88.0.tgz -> ❌ qs-6.5.2.tgz (Vulnerable Library) |
High | 7.5 | qs-6.5.2.tgz | Upgrade to version: qs - 6.2.4,6.3.3,6.4.1,6.5.3,6.6.1,6.7.3,6.8.3,6.9.7,6.10.3 | #267 |
CVE-2022-24785Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> react-devtools-extensions-0.0.0.tgz (Root Library) -> web-ext-4.3.0.tgz -> bunyan-1.8.12.tgz -> ❌ moment-2.24.0.tgz (Vulnerable Library) |
High | 7.5 | moment-2.24.0.tgz | Upgrade to version: moment - 2.29.2 | #194 |
CVE-2022-24772Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> react-devtools-extensions-0.0.0.tgz (Root Library) -> web-ext-4.3.0.tgz -> adbkit-2.11.1.tgz -> ❌ node-forge-0.7.6.tgz (Vulnerable Library) |
High | 7.5 | node-forge-0.7.6.tgz | Upgrade to version: node-forge - 1.3.0 | #185 |
CVE-2022-24772Path to dependency file: /fixtures/nesting/package.json Path to vulnerable library: /fixtures/nesting/node_modules/node-forge/package.json Dependency Hierarchy: -> react-scripts-3.4.1.tgz (Root Library) -> webpack-dev-server-3.10.3.tgz -> selfsigned-1.10.14.tgz -> ❌ node-forge-0.10.0.tgz (Vulnerable Library) |
High | 7.5 | node-forge-0.10.0.tgz | Upgrade to version: node-forge - 1.3.0 | #185 |
CVE-2022-24771Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> react-devtools-extensions-0.0.0.tgz (Root Library) -> web-ext-4.3.0.tgz -> adbkit-2.11.1.tgz -> ❌ node-forge-0.7.6.tgz (Vulnerable Library) |
High | 7.5 | node-forge-0.7.6.tgz | Upgrade to version: node-forge - 1.3.0 | #186 |
CVE-2022-24771Path to dependency file: /fixtures/nesting/package.json Path to vulnerable library: /fixtures/nesting/node_modules/node-forge/package.json Dependency Hierarchy: -> react-scripts-3.4.1.tgz (Root Library) -> webpack-dev-server-3.10.3.tgz -> selfsigned-1.10.14.tgz -> ❌ node-forge-0.10.0.tgz (Vulnerable Library) |
High | 7.5 | node-forge-0.10.0.tgz | Upgrade to version: node-forge - 1.3.0 | #186 |
CVE-2021-27292Path to dependency file: /fixtures/attribute-behavior/package.json Path to vulnerable library: /fixtures/attribute-behavior/package.json Dependency Hierarchy: -> react-dom-15.6.1.tgz (Root Library) -> fbjs-0.8.14.tgz -> ❌ ua-parser-js-0.7.14.tgz (Vulnerable Library) |
High | 7.5 | ua-parser-js-0.7.14.tgz | Upgrade to version: ua-parser-js - 0.7.24 | #14 |
CVE-2020-7793Path to dependency file: /fixtures/attribute-behavior/package.json Path to vulnerable library: /fixtures/attribute-behavior/package.json Dependency Hierarchy: -> react-dom-15.6.1.tgz (Root Library) -> fbjs-0.8.14.tgz -> ❌ ua-parser-js-0.7.14.tgz (Vulnerable Library) |
High | 7.5 | ua-parser-js-0.7.14.tgz | Upgrade to version: 0.7.23 | #130 |
CVE-2020-7733Path to dependency file: /fixtures/attribute-behavior/package.json Path to vulnerable library: /fixtures/attribute-behavior/package.json Dependency Hierarchy: -> react-dom-15.6.1.tgz (Root Library) -> fbjs-0.8.14.tgz -> ❌ ua-parser-js-0.7.14.tgz (Vulnerable Library) |
High | 7.5 | ua-parser-js-0.7.14.tgz | Upgrade to version: ua-parser-js - 0.7.22 | #20 |
CVE-2022-48285Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> react-devtools-extensions-0.0.0.tgz (Root Library) -> web-ext-4.3.0.tgz -> zip-dir-1.0.2.tgz -> ❌ jszip-2.6.1.tgz (Vulnerable Library) |
High | 7.3 | jszip-2.6.1.tgz | Upgrade to version: jszip - 3.8.0 | None |
CVE-2020-7720Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> react-devtools-extensions-0.0.0.tgz (Root Library) -> web-ext-4.3.0.tgz -> adbkit-2.11.1.tgz -> ❌ node-forge-0.7.6.tgz (Vulnerable Library) |
High | 7.3 | node-forge-0.7.6.tgz | Upgrade to version: node-forge - 0.10.0 | #150 |
WS-2022-0008Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> react-devtools-extensions-0.0.0.tgz (Root Library) -> web-ext-4.3.0.tgz -> adbkit-2.11.1.tgz -> ❌ node-forge-0.7.6.tgz (Vulnerable Library) |
Medium | 6.6 | node-forge-0.7.6.tgz | Upgrade to version: node-forge - 1.0.0 | #167 |
WS-2022-0008Path to dependency file: /fixtures/nesting/package.json Path to vulnerable library: /fixtures/nesting/node_modules/node-forge/package.json Dependency Hierarchy: -> react-scripts-3.4.1.tgz (Root Library) -> webpack-dev-server-3.10.3.tgz -> selfsigned-1.10.14.tgz -> ❌ node-forge-0.10.0.tgz (Vulnerable Library) |
Medium | 6.6 | node-forge-0.10.0.tgz | Upgrade to version: node-forge - 1.0.0 | #167 |
CVE-2023-46234Path to dependency file: /fixtures/packaging/browserify/dev/package.json Path to vulnerable library: /fixtures/packaging/browserify/dev/package.json,/fixtures/flight/package.json,/fixtures/blocks/package.json,/fixtures/expiration/package.json,/fixtures/concurrent/time-slicing/package.json,/fixtures/packaging/browserify/prod/package.json,/fixtures/attribute-behavior/package.json Dependency Hierarchy: -> react-scripts-1.1.4.tgz (Root Library) -> webpack-3.8.1.tgz -> node-libs-browser-2.1.0.tgz -> crypto-browserify-3.12.0.tgz -> ❌ browserify-sign-4.0.4.tgz (Vulnerable Library) |
Medium | 6.5 | browserify-sign-4.0.4.tgz | Upgrade to version: browserify-sign - 4.2.2 | None |
WS-2020-0217Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> react-devtools-extensions-0.0.0.tgz (Root Library) -> web-ext-4.3.0.tgz -> ❌ bunyan-1.8.12.tgz (Vulnerable Library) |
Medium | 6.2 | bunyan-1.8.12.tgz | Upgrade to version: bunyan - 1.8.13,2.0.3 | None |
CVE-2022-0235Path to dependency file: /fixtures/attribute-behavior/package.json Path to vulnerable library: /fixtures/attribute-behavior/package.json Dependency Hierarchy: -> react-dom-15.6.1.tgz (Root Library) -> fbjs-0.8.14.tgz -> isomorphic-fetch-2.2.1.tgz -> ❌ node-fetch-1.7.2.tgz (Vulnerable Library) |
Medium | 6.1 | node-fetch-1.7.2.tgz | Upgrade to version: node-fetch - 2.6.7,3.1.1 | #173 |
CVE-2022-0122Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> react-devtools-extensions-0.0.0.tgz (Root Library) -> web-ext-4.3.0.tgz -> adbkit-2.11.1.tgz -> ❌ node-forge-0.7.6.tgz (Vulnerable Library) |
Medium | 6.1 | node-forge-0.7.6.tgz | Upgrade to version: node-forge - 1.0.0 | #154 |
CVE-2022-0122Path to dependency file: /fixtures/nesting/package.json Path to vulnerable library: /fixtures/nesting/node_modules/node-forge/package.json Dependency Hierarchy: -> react-scripts-3.4.1.tgz (Root Library) -> webpack-dev-server-3.10.3.tgz -> selfsigned-1.10.14.tgz -> ❌ node-forge-0.10.0.tgz (Vulnerable Library) |
Medium | 6.1 | node-forge-0.10.0.tgz | Upgrade to version: node-forge - 1.0.0 | #154 |
CVE-2022-24773Path to dependency file: /package.json Path to vulnerable library: /package.json Dependency Hierarchy: -> react-devtools-extensions-0.0.0.tgz (Root Library) -> web-ext-4.3.0.tgz -> adbkit-2.11.1.tgz -> ❌ node-forge-0.7.6.tgz (Vulnerable Library) |
Medium | 5.3 | node-forge-0.7.6.tgz | Upgrade to version: node-forge - 1.3.0 | #184 |
✔️ Remediated vulnerabilities:
CVE | Vulnerable Library |
---|---|
CVE-2017-20165 | debug-2.2.0.tgz |
CVE-2021-23382 | postcss-5.2.15.tgz |
WS-2019-0032 | js-yaml-3.6.1.tgz |
CVE-2022-0235 | node-fetch-2.6.0.tgz |
CVE-2022-0691 | url-parse-1.1.7.tgz |
CVE-2017-20162 | ms-0.7.1.tgz |
CVE-2021-23490 | parse-link-header-1.0.1.tgz |
CVE-2022-37603 | loader-utils-2.0.0.tgz |
CVE-2021-23364 | browserslist-4.8.5.tgz |
WS-2019-0103 | handlebars-4.0.6.tgz |
CVE-2019-20920 | handlebars-4.0.6.tgz |
MSC-2023-16652 | fsevents-1.0.14.tgz |
CVE-2022-0686 | url-parse-1.1.8.tgz |
CVE-2023-28155 | request-2.79.0.tgz |
CVE-2021-32804 | tar-5.0.5.tgz |
CVE-2017-1000048 | qs-6.3.0.tgz |
CVE-2021-43138 | async-2.3.0.tgz |
CVE-2020-15366 | ajv-4.10.3.tgz |
CVE-2018-14732 | webpack-dev-server-1.16.2.tgz |
CVE-2022-0155 | follow-redirects-1.7.0.tgz |
CVE-2019-20922 | handlebars-4.0.6.tgz |
WS-2019-0063 | js-yaml-3.6.1.tgz |
CVE-2022-0691 | url-parse-1.1.8.tgz |
CVE-2022-0686 | url-parse-1.1.7.tgz |
CVE-2022-0512 | url-parse-1.1.8.tgz |
CVE-2017-1000427 | marked-0.3.6.tgz |
CVE-2018-3737 | sshpk-1.11.0.tgz |
CVE-2021-32640 | ws-6.1.2.tgz |
CVE-2021-32640 | ws-7.3.1.tgz |
WS-2018-0589 | nwmatcher-1.3.9.tgz |
CVE-2021-23364 | browserslist-4.14.0.tgz |
CVE-2017-18077 | brace-expansion-1.1.6.tgz |
WS-2018-0069 | is-my-json-valid-2.15.0.tgz |
WS-2019-0027 | marked-0.3.6.tgz |
CVE-2019-19919 | handlebars-4.0.6.tgz |
CVE-2021-23337 | lodash-4.17.19.tgz |
CVE-2022-46175 | json5-0.4.0.tgz |
CVE-2021-23386 | dns-packet-1.1.1.tgz |
CVE-2022-37599 | loader-utils-2.0.0.tgz |
CVE-2020-15168 | node-fetch-2.6.0.tgz |
CVE-2022-21213 | mout-1.1.0.tgz |
CVE-2020-28500 | lodash-4.17.19.tgz |
WS-2020-0127 | npm-registry-fetch-6.0.0.tgz |
CVE-2022-37620 | html-minifier-3.2.3.tgz |
CVE-2021-23369 | handlebars-4.0.6.tgz |
CVE-2018-3750 | deep-extend-0.4.1.tgz |
CVE-2022-0512 | url-parse-1.1.7.tgz |
CVE-2022-21681 | marked-0.3.6.tgz |
CVE-2022-46175 | json5-2.1.0.tgz |
CVE-2022-24785 | moment-2.18.1.tgz |
CVE-2020-8124 | url-parse-1.1.8.tgz |
CVE-2021-23364 | browserslist-4.13.0.tgz |
CVE-2017-16099 | no-case-2.3.0.tgz |
CVE-2021-23362 | hosted-git-info-2.1.5.tgz |
CVE-2021-37713 | tar-5.0.5.tgz |
WS-2018-0076 | tunnel-agent-0.4.3.tgz |
CVE-2018-20835 | tar-fs-1.16.0.tgz |
CVE-2022-0639 | url-parse-1.1.7.tgz |
WS-2019-0064 | handlebars-4.0.6.tgz |
CVE-2021-3664 | url-parse-1.1.8.tgz |
WS-2018-0590 | diff-3.2.0.tgz |
CVE-2020-15366 | ajv-4.10.4.tgz |
CVE-2020-28469 | glob-parent-5.1.1.tgz |
WS-2018-0628 | marked-0.3.6.tgz |
CVE-2020-15366 | ajv-4.11.5.tgz |
CVE-2020-8124 | url-parse-1.1.7.tgz |
WS-2018-0347 | eslint-3.16.1.tgz |
CVE-2021-27515 | url-parse-1.1.8.tgz |
CVE-2018-16492 | extend-3.0.0.tgz |
WS-2018-0069 | is-my-json-valid-2.16.0.tgz |
CVE-2018-3774 | url-parse-1.1.8.tgz |
CVE-2021-37712 | tar-5.0.5.tgz |
CVE-2017-16119 | fresh-0.3.0.tgz |
CVE-2020-7789 | node-notifier-4.6.1.tgz |
CVE-2022-31129 | moment-2.18.1.tgz |
CVE-2017-16028 | randomatic-1.1.6.tgz |
CVE-2017-16032 | brace-expansion-1.1.6.tgz |
CVE-2022-0639 | url-parse-1.1.8.tgz |
CVE-2021-3664 | url-parse-1.1.7.tgz |
CVE-2022-37601 | loader-utils-2.0.0.tgz |
CVE-2017-16042 | growl-1.8.1.tgz |
CVE-2021-23383 | handlebars-4.0.6.tgz |
CVE-2020-7792 | mout-1.1.0.tgz |
CVE-2021-37701 | tar-5.0.5.tgz |
CVE-2017-20165 | debug-2.6.0.tgz |
CVE-2017-16137 | debug-2.2.0.tgz |
WS-2019-0025 | marked-0.3.6.tgz |
CVE-2021-27515 | url-parse-1.1.7.tgz |
CVE-2021-23362 | hosted-git-info-3.0.2.tgz |
WS-2019-0017 | clean-css-4.0.11.tgz |
CVE-2022-24999 | qs-6.2.0.tgz |
CVE-2017-16138 | mime-1.2.11.tgz |
CVE-2019-13173 | fstream-1.0.10.tgz |
CVE-2019-15599 | tree-kill-1.1.0.tgz |
CVE-2017-18214 | moment-2.18.1.tgz |
CVE-2018-1107 | is-my-json-valid-2.16.0.tgz |
WS-2020-0344 | is-my-json-valid-2.16.0.tgz |
WS-2020-0450 | handlebars-4.0.6.tgz |
CVE-2017-16137 | debug-2.6.0.tgz |
CVE-2021-23362 | hosted-git-info-2.4.1.tgz |
WS-2020-0344 | is-my-json-valid-2.15.0.tgz |
CVE-2021-23382 | postcss-5.2.8.tgz |
CVE-2018-1107 | is-my-json-valid-2.15.0.tgz |
CVE-2021-23382 | postcss-6.0.23.tgz |
WS-2018-0107 | open-0.0.5.tgz |
CVE-2017-16114 | marked-0.3.6.tgz |
CVE-2020-8244 | bl-3.0.0.tgz |
WS-2020-0163 | marked-0.3.6.tgz |
CVE-2021-24033 | react-dev-utils-0.5.2.tgz |
CVE-2021-23382 | postcss-5.2.16.tgz |
CVE-2017-1000048 | qs-6.2.0.tgz |
CVE-2022-21680 | marked-0.3.6.tgz |
CVE-2021-43138 | async-2.1.4.tgz |
CVE-2018-3774 | url-parse-1.1.7.tgz |
WS-2019-0017 | clean-css-3.4.23.tgz |
CVE-2022-37620 | html-minifier-3.4.2.tgz |
CVE-2021-23424 | ansi-html-0.0.5.tgz |
WS-2020-0342 | is-my-json-valid-2.16.0.tgz |
CVE-2019-5786 | puppeteer-1.11.0.tgz |
CVE-2021-32803 | tar-5.0.5.tgz |
WS-2020-0091 | http-proxy-1.17.0.tgz |
CVE-2018-3737 | sshpk-1.10.1.tgz |
WS-2020-0342 | is-my-json-valid-2.15.0.tgz |
CVE-2021-4245 | rfc6902-3.0.4.tgz |
WS-2019-0026 | marked-0.3.6.tgz |
CVE-2022-37601 | loader-utils-0.2.16.tgz |
CVE-2022-25858 | terser-4.8.0.tgz |
Base branch total remaining vulnerabilities: 531
Base branch commit: null
Total libraries scanned: 4105
Scan token: 8e526b247d9443e5b53844a39b47fba8