Morsmalleo / AhMyth

Cross-Platform Android Remote Administration Tool | Official maintained repository for the AhMyth R.A.T Project | A dedicated revival of the original repository at https://GitHub.com/AhMyth/AhMyth-Android-RAT
GNU General Public License v3.0
780 stars 191 forks source link

[Snyk] Fix for 1 vulnerabilities #461

Closed Morsmalleo closed 9 months ago

Morsmalleo commented 9 months ago

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

#### Changes included in this PR - Changes to the following files to upgrade the vulnerable dependencies to a fixed version: - AhMyth-Server/app/node_modules/socket.io/package.json #### Vulnerabilities that will be fixed ##### With an upgrade: Severity | Priority Score (*) | Issue | Breaking Change | Exploit Maturity :-------------------------:|-------------------------|:-------------------------|:-------------------------|:------------------------- ![low severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/l.png "low severity") | **506/1000**
**Why?** Proof of Concept exploit, Has a fix available, CVSS 3.7 | Regular Expression Denial of Service (ReDoS)
[npm:debug:20170905](https://snyk.io/vuln/npm:debug:20170905) | Yes | Proof of Concept (*) Note that the real score may have changed since the PR was raised.
Commit messages
Package name: debug The new version differs by 34 commits.
  • 0d3d66b 4.3.1
  • b6d12fd fix regression
  • 3f56313 4.3.0
  • e2d3bc9 add deprecation notice for debug.destroy()
  • 72e7f86 fix memory leak within debug instance
  • 27152ca add test for enable/disable of existing instances
  • 22e13fe fix quoted percent sign
  • 80ef62a 4.2.0
  • 09914af Marks supports-color as an *optional* peer dependency
  • db306db Update and pin ms to 2.1.2
  • 6b07f9e Fixes: Unable to take control over selectColor #747
  • 0c1d518 remove dead code and fix lowercase comment (for linter)
  • 4acdeed run linter inside of test script
  • 3f4d724 Add "engines" to `package.json` (#680)
  • 608fca9 Update ISSUE_TEMPLATE.md
  • 5c7c61d fix links in issue templates
  • 976f8d2 add issue and pull request templates
  • 982c12c test: only run coveralls on travis
  • 825d35a copy custom logger to namespace extension (fixes #646)
  • 5528572 use console.debug() in browser when available (closes #600)
  • c0127b1 remove examples folder (closes #650)
  • 94583b6 remove build system (closes #652)
  • 0e94034 update development dependencies
  • ad551e2 add Josh Junon to contributors
See the full diff
Package name: engine.io The new version differs by 46 commits.
  • 9b62152 chore(release): 4.0.6
  • 5a91253 chore: bump ws and debug versions
  • fffa0a3 chore: update GitHub issue templates
  • cec2750 fix: correctly pass the options when using the Server constructor (#610)
  • 04ea358 docs(changelog): include changelog for release 3.5.0
  • e7115b8 chore(release): 4.0.5
  • f5efa1e refactor: use ES6 syntax for the tests
  • 312bd35 ci: migrate to GitHub Actions
  • c2981c6 chore(release): 4.0.4
  • 67ca12c chore(release): 4.0.3
  • 9ddccf3 chore: bump engine.io-client
  • 16fd658 chore(release): 4.0.2
  • 17b8c2f fix: add extension in the package.json main entry (#608)
  • 3284208 chore: bump engine.io-client
  • 58943c3 chore(release): 4.0.1
  • c099338 refactor: remove binary handling for the polling transport
  • fe093ba fix: do not overwrite CORS headers upon error
  • f9c0e74 chore: bump eiows to 3.3.2
  • a05379b test: use eiows
  • 428b4f5 docs: update links to other repositories
  • ec83022 docs: update examples with ES6 syntax
  • 6092239 docs: update latency example
  • 70b1c36 chore(release): 4.0.0
  • 9df38d5 docs: update the list of supported engines
See the full diff
Package name: socket.io-parser The new version differs by 31 commits.
  • 444520d chore(release): 4.0.3
  • b076dbb ci: migrate to GitHub Actions
  • 7c380d3 chore: bump debug version
  • f2098b0 chore(release): 4.0.2
  • 66973a3 chore: cleanup dist folder before compilation
  • 4efa005 fix: move @ types/component-emitter to dependencies (#99)
  • c044433 docs: add compatibility table
  • e339323 chore(release): 4.0.1
  • 412769f chore(release): 4.0.1-rc3
  • db1d274 refactor: rename ERROR to CONNECT_ERROR
  • e3d272f docs: fix small typo (#98)
  • 64b6648 chore(release): 4.0.1-rc2
  • 58b3d09 chore: protocol version 5
  • 285e7cd feat: move binary detection back to the parser
  • 7fc3c42 chore(release): 4.0.1-rc1
  • 78f9fc2 feat: add support for a payload in a CONNECT packet
  • 9eb8561 refactor: use require for debug dependency
  • 091d25e chore: add dist
  • ccadd5a docs(changelog): include changelog for release 3.3.1
  • c04d7f5 chore(release): 4.0.0
  • 9e601c6 refactor: export Packet interface and refactor imports
  • cfdc479 refactor: use prettier to format test code
  • 28d4f03 refactor: do not convert Blobs
  • fe33ff7 test: actually test the parser
See the full diff
Check the changes in this PR to ensure they won't cause issues with your project. ------------ **Note:** *You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.* For more information: 🧐 [View latest project report](https://app.snyk.io/org/morsmalleo/project/0df39b2a-fa57-4e41-8de1-e6681bec7350?utm_source=github&utm_medium=referral&page=fix-pr) 🛠 [Adjust project settings](https://app.snyk.io/org/morsmalleo/project/0df39b2a-fa57-4e41-8de1-e6681bec7350?utm_source=github&utm_medium=referral&page=fix-pr/settings) 📚 [Read more about Snyk's upgrade and patch logic](https://support.snyk.io/hc/en-us/articles/360003891078-Snyk-patches-to-fix-vulnerabilities) [//]: # (snyk:metadata:{"prId":"0f3a0533-054a-4628-9ee8-c7772d4cfce1","prPublicId":"0f3a0533-054a-4628-9ee8-c7772d4cfce1","dependencies":[{"name":"debug","from":"4.1.1","to":"4.3.1"},{"name":"engine.io","from":"3.6.1","to":"4.0.6"},{"name":"socket.io-parser","from":"3.4.3","to":"4.0.3"}],"packageManager":"npm","projectPublicId":"0df39b2a-fa57-4e41-8de1-e6681bec7350","projectUrl":"https://app.snyk.io/org/morsmalleo/project/0df39b2a-fa57-4e41-8de1-e6681bec7350?utm_source=github&utm_medium=referral&page=fix-pr","type":"auto","patch":[],"vulns":["npm:debug:20170905"],"upgrade":["npm:debug:20170905"],"isBreakingChange":true,"env":"prod","prType":"fix","templateVariants":["priorityScore"],"priorityScoreList":[506],"remediationStrategy":"vuln"}) --- **Learn how to fix vulnerabilities with free interactive lessons:** 🦉 [Regular Expression Denial of Service (ReDoS)](https://learn.snyk.io/lesson/redos/?loc=fix-pr)