VilnaCRM-Org / website

Creative Commons Zero v1.0 Universal
0 stars 0 forks source link

[Snyk] Fix for 7 vulnerabilities #16

Closed Vlas-Pravsha closed 8 months ago

Vlas-Pravsha commented 9 months ago

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

#### Changes included in this PR - Changes to the following files to upgrade the vulnerable dependencies to a fixed version: - package.json #### Vulnerabilities that will be fixed ##### With an upgrade: Severity | Priority Score (*) | Issue | Breaking Change | Exploit Maturity :-------------------------:|-------------------------|:-------------------------|:-------------------------|:------------------------- ![medium severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/m.png "medium severity") | **646/1000**
**Why?** Proof of Concept exploit, Has a fix available, CVSS 6.5 | Server-side Request Forgery (SSRF)
[SNYK-JS-CYPRESSREQUEST-5871337](https://snyk.io/vuln/SNYK-JS-CYPRESSREQUEST-5871337) | Yes | Proof of Concept ![medium severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/m.png "medium severity") | **586/1000**
**Why?** Proof of Concept exploit, Has a fix available, CVSS 5.3 | Regular Expression Denial of Service (ReDoS)
[SNYK-JS-GLOBPARENT-1016905](https://snyk.io/vuln/SNYK-JS-GLOBPARENT-1016905) | Yes | Proof of Concept ![medium severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/m.png "medium severity") | **484/1000**
**Why?** Has a fix available, CVSS 5.4 | Open Redirect
[SNYK-JS-GOT-2932019](https://snyk.io/vuln/SNYK-JS-GOT-2932019) | Yes | No Known Exploit ![medium severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/m.png "medium severity") | **631/1000**
**Why?** Proof of Concept exploit, Has a fix available, CVSS 6.2 | Missing Release of Resource after Effective Lifetime
[SNYK-JS-INFLIGHT-6095116](https://snyk.io/vuln/SNYK-JS-INFLIGHT-6095116) | Yes | Proof of Concept ![medium severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/m.png "medium severity") | **626/1000**
**Why?** Proof of Concept exploit, Has a fix available, CVSS 6.1 | Cross-site Scripting (XSS)
[SNYK-JS-SERIALIZEJAVASCRIPT-6147607](https://snyk.io/vuln/SNYK-JS-SERIALIZEJAVASCRIPT-6147607) | Yes | Proof of Concept ![high severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/h.png "high severity") | **696/1000**
**Why?** Proof of Concept exploit, Has a fix available, CVSS 7.5 | Regular Expression Denial of Service (ReDoS)
[SNYK-JS-TRIM-1017038](https://snyk.io/vuln/SNYK-JS-TRIM-1017038) | Yes | Proof of Concept ![high severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/h.png "high severity") | **589/1000**
**Why?** Has a fix available, CVSS 7.5 | Prototype Pollution
[SNYK-JS-UNSETVALUE-2400660](https://snyk.io/vuln/SNYK-JS-UNSETVALUE-2400660) | Yes | No Known Exploit (*) Note that the real score may have changed since the PR was raised.
Commit messages
Package name: storybook The new version differs by 250 commits.
  • 51608c8 Bump version from "7.1.0-rc.2" to "7.1.0" [skip ci]
  • 99088fd Merge pull request #23473 from storybookjs/version-prerelease-from-7.1.0-rc.2
  • 9e8912c Update CHANGELOG.md [skip ci]
  • 7862f9e Write changelog for 7.1.0
  • 80edfa4 Merge pull request #23475 from storybookjs/fix/lint-issue
  • 027ef0c remove unused import
  • fa8c5f6 Merge pull request #23472 from storybookjs/fix/improve-svelte-error
  • 29a1103 move error message from log to error
  • 4c371e0 Merge pull request #23471 from storybookjs/update-pr-template
  • 1161323 Update PULL_REQUEST_TEMPLATE.md
  • fdd07b7 fix typo
  • 36935e9 Restore prerelease changelogs before 7.1.0-alpha.30
  • 3531eb3 Merge pull request #23186 from re-taro/fix/jsdoc
  • 9f9070d Merge pull request #23444 from storybookjs/chore_docs_adds_mdx_video_callout
  • f88a170 Merge branch 'next' into chore_docs_adds_mdx_video_callout
  • 6c733aa Merge pull request #23439 from storybookjs/chore_docs_autodocs_toc
  • 2035c5f Addressing feedback
  • 59c3af4 Adds MDX video callout
  • cfcb363 Merge pull request #23442 from storybookjs/chore_docs_web_snippets_fix
  • 950218f Fixes autodocs webcomponents snippets
  • e7479e7 Bump version from "7.1.0-rc.1" to "7.1.0-rc.2" [skip ci]
  • c1b4e2e Merge pull request #23414 from storybookjs/version-prerelease-from-7.1.0-rc.1
  • 4124e95 Write changelog for 7.1.0-rc.2
  • 15f6768 Adds TOC documentation
See the full diff
Check the changes in this PR to ensure they won't cause issues with your project. ------------ **Note:** *You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.* For more information: 🧐 [View latest project report](https://app.snyk.io/org/vlas-pravsha/project/8a298432-5cdb-427c-af49-1a284ddfc4fd?utm_source=github&utm_medium=referral&page=fix-pr) 🛠 [Adjust project settings](https://app.snyk.io/org/vlas-pravsha/project/8a298432-5cdb-427c-af49-1a284ddfc4fd?utm_source=github&utm_medium=referral&page=fix-pr/settings) 📚 [Read more about Snyk's upgrade and patch logic](https://support.snyk.io/hc/en-us/articles/360003891078-Snyk-patches-to-fix-vulnerabilities) [//]: # (snyk:metadata:{"prId":"f631ee74-9de3-476e-adb9-12049c36cbe2","prPublicId":"f631ee74-9de3-476e-adb9-12049c36cbe2","dependencies":[{"name":"cypress","from":"11.2.0","to":"13.0.0"},{"name":"storybook","from":"6.5.16","to":"7.1.0"}],"packageManager":"npm","projectPublicId":"8a298432-5cdb-427c-af49-1a284ddfc4fd","projectUrl":"https://app.snyk.io/org/vlas-pravsha/project/8a298432-5cdb-427c-af49-1a284ddfc4fd?utm_source=github&utm_medium=referral&page=fix-pr","type":"user-initiated","patch":[],"vulns":["SNYK-JS-CYPRESSREQUEST-5871337","SNYK-JS-GLOBPARENT-1016905","SNYK-JS-GOT-2932019","SNYK-JS-INFLIGHT-6095116","SNYK-JS-SERIALIZEJAVASCRIPT-6147607","SNYK-JS-TRIM-1017038","SNYK-JS-UNSETVALUE-2400660"],"upgrade":["SNYK-JS-CYPRESSREQUEST-5871337","SNYK-JS-GLOBPARENT-1016905","SNYK-JS-GOT-2932019","SNYK-JS-INFLIGHT-6095116","SNYK-JS-SERIALIZEJAVASCRIPT-6147607","SNYK-JS-TRIM-1017038","SNYK-JS-UNSETVALUE-2400660"],"isBreakingChange":true,"env":"prod","prType":"fix","templateVariants":["priorityScore"],"priorityScoreList":[646,586,484,631,626,696,589],"remediationStrategy":"vuln"}) --- **Learn how to fix vulnerabilities with free interactive lessons:** 🦉 [Server-side Request Forgery (SSRF)](https://learn.snyk.io/lesson/ssrf-server-side-request-forgery/?loc=fix-pr) 🦉 [Regular Expression Denial of Service (ReDoS)](https://learn.snyk.io/lesson/redos/?loc=fix-pr) 🦉 [Open Redirect](https://learn.snyk.io/lesson/open-redirect/?loc=fix-pr) 🦉 [More lessons are available in Snyk Learn](https://learn.snyk.io/?loc=fix-pr)