FlorentinTh / LE2ML-API

Repository of the API for the LE2ML workbench.
Apache License 2.0
1 stars 0 forks source link

[Snyk] Upgrade mongoose from 6.4.1 to 6.12.8 #958

Open FlorentinTh opened 5 months ago

FlorentinTh commented 5 months ago

This PR was automatically created by Snyk using the credentials of a real user.


![snyk-top-banner](https://github.com/andygongea/OWASP-Benchmark/assets/818805/c518c423-16fe-447e-b67f-ad5a49b5d123)

Snyk has created this PR to upgrade mongoose from 6.4.1 to 6.12.8.

:information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
- The recommended version is **57 versions** ahead of your current version. - The recommended version was released on **2 months ago**. #### Issues fixed by the recommended upgrade: | | Issue | Score | Exploit Maturity | :-------------------------:|:-------------------------|:-------------------------|:------------------------- ![high severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/h.png 'high severity') | Prototype Pollution
[SNYK-JS-MONGOOSE-5777721](https://snyk.io/vuln/SNYK-JS-MONGOOSE-5777721) | **726** | Proof of Concept ![high severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/h.png 'high severity') | Server-side Request Forgery (SSRF)
[SNYK-JS-IP-6240864](https://snyk.io/vuln/SNYK-JS-IP-6240864) | **726** | Proof of Concept ![high severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/h.png 'high severity') | Prototype Pollution
[SNYK-JS-MONGOOSE-2961688](https://snyk.io/vuln/SNYK-JS-MONGOOSE-2961688) | **726** | Proof of Concept ![medium severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/m.png 'medium severity') | Server-Side Request Forgery (SSRF)
[SNYK-JS-IP-7148531](https://snyk.io/vuln/SNYK-JS-IP-7148531) | **726** | Proof of Concept ![medium severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/m.png 'medium severity') | Information Exposure
[SNYK-JS-MONGODB-5871303](https://snyk.io/vuln/SNYK-JS-MONGODB-5871303) | **726** | No Known Exploit
Release notes
Package name: mongoose
  • 6.12.8 - 2024-04-10

    chore: release 6.12.8

      </li>
      <li>
        <b>6.12.7</b> - 2024-03-01
      </li>
      <li>
        <b>6.12.6</b> - 2024-01-22
      </li>
      <li>
        <b>6.12.5</b> - 2024-01-03
      </li>
      <li>
        <b>6.12.4</b> - 2023-12-27
      </li>
      <li>
        <b>6.12.3</b> - 2023-11-07
      </li>
      <li>
        <b>6.12.2</b> - 2023-10-25
      </li>
      <li>
        <b>6.12.1</b> - 2023-10-12
      </li>
      <li>
        <b>6.12.0</b> - 2023-08-24
      </li>
      <li>
        <b>6.11.6</b> - 2023-08-21
      </li>
      <li>
        <b>6.11.5</b> - 2023-08-01
      </li>
      <li>
        <b>6.11.4</b> - 2023-07-17
      </li>
      <li>
        <b>6.11.3</b> - 2023-07-11
      </li>
      <li>
        <b>6.11.2</b> - 2023-06-08
      </li>
      <li>
        <b>6.11.1</b> - 2023-05-08
      </li>
      <li>
        <b>6.11.0</b> - 2023-05-01
      </li>
      <li>
        <b>6.10.5</b> - 2023-04-06
      </li>
      <li>
        <b>6.10.4</b> - 2023-03-21
      </li>
      <li>
        <b>6.10.3</b> - 2023-03-13
      </li>
      <li>
        <b>6.10.2</b> - 2023-03-07
      </li>
      <li>
        <b>6.10.1</b> - 2023-03-03
      </li>
      <li>
        <b>6.10.0</b> - 2023-02-22
      </li>
      <li>
        <b>6.9.3</b> - 2023-02-22
      </li>
      <li>
        <b>6.9.2</b> - 2023-02-16
      </li>
      <li>
        <b>6.9.1</b> - 2023-02-06
      </li>
      <li>
        <b>6.9.0</b> - 2023-01-25
      </li>
      <li>
        <b>6.8.4</b> - 2023-01-17
      </li>
      <li>
        <b>6.8.3</b> - 2023-01-06
      </li>
      <li>
        <b>6.8.2</b> - 2022-12-28
      </li>
      <li>
        <b>6.8.1</b> - 2022-12-19
      </li>
      <li>
        <b>6.8.0</b> - 2022-12-05
      </li>
      <li>
        <b>6.7.5</b> - 2022-11-30
      </li>
      <li>
        <b>6.7.4</b> - 2022-11-28
      </li>
      <li>
        <b>6.7.3</b> - 2022-11-22
      </li>
      <li>
        <b>6.7.2</b> - 2022-11-07
      </li>
      <li>
        <b>6.7.1</b> - 2022-11-02
      </li>
      <li>
        <b>6.7.0</b> - 2022-10-24
      </li>
      <li>
        <b>6.6.7</b> - 2022-10-21
      </li>
      <li>
        <b>6.6.6</b> - 2022-10-20
      </li>
      <li>
        <b>6.6.5</b> - 2022-10-05
      </li>
      <li>
        <b>6.6.4</b> - 2022-10-03
      </li>
      <li>
        <b>6.6.3</b> - 2022-09-30
      </li>
      <li>
        <b>6.6.2</b> - 2022-09-26
      </li>
      <li>
        <b>6.6.1</b> - 2022-09-14
      </li>
      <li>
        <b>6.6.0</b> - 2022-09-08
      </li>
      <li>
        <b>6.5.5</b> - 2022-09-07
      </li>
      <li>
        <b>6.5.4</b> - 2022-08-30
      </li>
      <li>
        <b>6.5.3</b> - 2022-08-25
      </li>
      <li>
        <b>6.5.2</b> - 2022-08-10
      </li>
      <li>
        <b>6.5.1</b> - 2022-08-03
      </li>
      <li>
        <b>6.5.0</b> - 2022-07-26
      </li>
      <li>
        <b>6.4.7</b> - 2022-07-25
      </li>
      <li>
        <b>6.4.6</b> - 2022-07-20
      </li>
      <li>
        <b>6.4.5</b> - 2022-07-18
      </li>
      <li>
        <b>6.4.4</b> - 2022-07-08
      </li>
      <li>
        <b>6.4.3</b> - 2022-07-05
      </li>
      <li>
        <b>6.4.2</b> - 2022-07-01
      </li>
      <li>
        <b>6.4.1</b> - 2022-06-27
      </li>
    </ul>
    from <a href="https://github.com/Automattic/mongoose/releases">mongoose GitHub release notes</a>


[!IMPORTANT]

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • This PR was automatically created by Snyk using the credentials of a real user.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information: