Closed vaibhavyadav-dev closed 1 month ago
@vaibhavyadav-dev I can look into this one, can you please assign this to me?
@vaibhavyadav-dev PR has been submitted to address this issue https://github.com/BharatSeva/BharatSeva-Plus-User-Interface/pull/28
ok @kalyan90
Description
A number of vulnerabilities were detected in the following NPM packages. Immediate action is required to mitigate potential security risks.
List of Vulnerabilities:
Babel - Arbitrary code execution Severity: Critical
Affected Package: babel/traverse
path-to-regexp - Backtracking regular expressions Severity: High
Affected Package: path-to-regexp
axios - Server-Side Request Forgery Severity: High
Affected Package: axios
braces - Uncontrolled resource consumption Severity: High
Affected Package: braces
semver - Regular Expression Denial of Service (ReDoS) Severity: High
Affected Package: semver
nth-check - Inefficient Regular Expression Complexity Severity: High
Affected Package: nth-check
rollup - DOM Clobbering Gadget leads to XSS Severity: High
Affected Package: rollup
body-parser - Denial of Service with URL Encoding Severity: High
Affected Package: body-parser
@adobe/css-tools - ReDoS while parsing CSS Severity: Moderate
Affected Package: @adobe/css-tools
Steps to Reproduce:
package-lock.json
.Expected Outcome:
Labels: