Open sauntimo opened 9 months ago
Semgrep found 1 ssc-45c7ee79-f517-41e2-b61a-45743d9df9c6
finding:
Risk: Affected version of handlebars is vulnerable to Improper Neutralization Of Special Elements In Output Used By A Downstream Component ('Injection') / Improperly Controlled Modification Of Object Prototype Attributes ('Prototype Pollution'). The vulnerability allows for Prototype Pollution, potentially leading to Remote Code Execution, as templates can modify an object's__proto__
and __defineGetter__
properties, enabling attackers to execute arbitrary code using specially crafted payloads.
Fix: Upgrade this library to at least version 4.3.0 at auth0-authorization-extension/package-lock.json:24372.
Reference(s): https://github.com/advisories/GHSA-w457-6q6x-cgp9, CVE-2019-19919
Ignore this finding from ssc-45c7ee79-f517-41e2-b61a-45743d9df9c6.
βοΈ Changes
π· Screenshots
If there were visual changes to the application with this change, please include before and after screenshots here. If it has animation, please use screen capture software like to make a gif.
π References
π― Testing
β π« This change has been tested in a Webtask
β π« This change has unit test coverage
β π« This change has integration test coverage
β π« This change has been tested for performance
π Deployment
β π« This can be deployed any time
π‘ Rollout
In order to verify that the deployment was successful we will β¦
π₯ Rollback
We will rollback if β¦
π Procedure
π₯ Appliance
Note to reviewers: ensure that this change is compatible with the Appliance.