agmoyano / node-jasper

JasperReports from Node.js
83 stars 51 forks source link

Vulnerability issues on latest nodejs #74

Open corpuzjholand opened 2 years ago

corpuzjholand commented 2 years ago

async 2.0.0 - 2.6.3 Severity: high Prototype Pollution in async - https://github.com/advisories/GHSA-fwr7-v2mv-hh25 No fix available node_modules/java/node_modules/async java 0.8.0 - 0.12.2 Depends on vulnerable versions of async node_modules/java node-jasper * Depends on vulnerable versions of extend Depends on vulnerable versions of java node_modules/node-jasper

extend <2.0.2 Severity: moderate Prototype Pollution in extend - https://github.com/advisories/GHSA-qrmc-fj45-qfc2 No fix available node_modules/extend