auth0 / auth0-authorization-extension

Auth0 Extension that adds authorization features to your account
https://auth0.com/docs/extensions/authorization-extension/v2
Other
82 stars 55 forks source link

[Snyk] Security upgrade auth0 from 2.14.0 to 4.0.0 #381

Closed MarcinHoppe closed 5 months ago

MarcinHoppe commented 7 months ago

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.

#### Changes included in this PR - Changes to the following files to upgrade the vulnerable dependencies to a fixed version: - package.json - package-lock.json #### Vulnerabilities that will be fixed ##### With an upgrade: Severity | Priority Score (*) | Issue | Breaking Change | Exploit Maturity :-------------------------:|-------------------------|:-------------------------|:-------------------------|:------------------------- ![medium severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/m.png "medium severity") | **586/1000**
**Why?** Proof of Concept exploit, Has a fix available, CVSS 5.3 | Regular Expression Denial of Service (ReDoS)
[SNYK-JS-COOKIEJAR-3149984](https://snyk.io/vuln/SNYK-JS-COOKIEJAR-3149984) | Yes | Proof of Concept ![high severity](https://res.cloudinary.com/snyk/image/upload/w_20,h_20/v1561977819/icon/h.png "high severity") | **696/1000**
**Why?** Proof of Concept exploit, Has a fix available, CVSS 7.5 | Prototype Poisoning
[SNYK-JS-QS-3153490](https://snyk.io/vuln/SNYK-JS-QS-3153490) | Yes | Proof of Concept (*) Note that the real score may have changed since the PR was raised.
Commit messages
Package name: auth0 The new version differs by 250 commits.
  • 3c4ac31 Release v4.0.0 (#936)
  • 27bac79 Release v4.0.0
  • 56614a4 [SDK-4559] Merge Beta to prepare for v4 GA Release (#935)
  • c557474 [SDK-4559] Prepare to be merged into master for release (#934)
  • 54a72c9 Release v4.0.0-beta.10 (#933)
  • 20d5766 Merge branch 'master' into beta
  • 2939c8c [SDK-4548] Support optional responses (#928)
  • a9cb47e Release v3.7.1 (#932)
  • f2896f4 Update v4_MIGRATION_GUIDE.md
  • 2fc510d fix: ManagementTokenProvider should also respect the keepAlive config option (#927)
  • f1c6646 mark user_id as required for grants.deleteByUserId (#930)
  • 7a43260 add fields and include_fields to organization.getMembers (#929)
  • 279b981 add pagination overloads to `client.getAll()` (#931)
  • 986ccd7 Release v4.0.0-beta.9 (#926)
  • dbab12b Rename fetch option, add request examples (#923)
  • 42e14fe Add `fields` to migration guide (#925)
  • b27009e Change client id params to client_id (#924)
  • d10c97a Release v3.7.0 (#922)
  • 01b9336 feat: add configuration for using persistent connections (#919)
  • f695697 Avoid optional properties on responses where possible (#921)
  • 3371afc Bring back latest beta docs (#920)
  • 2efc2b5 Add publint (#918)
  • 03f0481 Release v4.0.0-beta.8 (#917)
  • fe6315a Release v3.6.1 (#916)
See the full diff
Check the changes in this PR to ensure they won't cause issues with your project. ------------ **Note:** *You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.* For more information: šŸ§ [View latest project report](https://app.snyk.io/org/auth0-platform-security-test/project/6ce97070-4131-4e28-8737-ec2759f7aeab?utm_source=github&utm_medium=referral&page=fix-pr) šŸ›  [Adjust project settings](https://app.snyk.io/org/auth0-platform-security-test/project/6ce97070-4131-4e28-8737-ec2759f7aeab?utm_source=github&utm_medium=referral&page=fix-pr/settings) šŸ“š [Read more about Snyk's upgrade and patch logic](https://support.snyk.io/hc/en-us/articles/360003891078-Snyk-patches-to-fix-vulnerabilities) [//]: # (snyk:metadata:{"prId":"fb832401-2076-4b2a-9a80-7ac1f69ff9ab","prPublicId":"fb832401-2076-4b2a-9a80-7ac1f69ff9ab","dependencies":[{"name":"auth0","from":"2.14.0","to":"4.0.0"}],"packageManager":"npm","projectPublicId":"6ce97070-4131-4e28-8737-ec2759f7aeab","projectUrl":"https://app.snyk.io/org/auth0-platform-security-test/project/6ce97070-4131-4e28-8737-ec2759f7aeab?utm_source=github&utm_medium=referral&page=fix-pr","type":"auto","patch":[],"vulns":["SNYK-JS-COOKIEJAR-3149984","SNYK-JS-QS-3153490"],"upgrade":["SNYK-JS-COOKIEJAR-3149984","SNYK-JS-QS-3153490"],"isBreakingChange":true,"env":"prod","prType":"fix","templateVariants":["updated-fix-title","priorityScore"],"priorityScoreList":[586,696],"remediationStrategy":"vuln"}) --- **Learn how to fix vulnerabilities with free interactive lessons:** šŸ¦‰ [Regular Expression Denial of Service (ReDoS)](https://learn.snyk.io/lesson/redos/?loc=fix-pr) šŸ¦‰ [Prototype Poisoning](https://learn.snyk.io/lesson/prototype-pollution/?loc=fix-pr) [SDK-4559]: https://auth0team.atlassian.net/browse/SDK-4559?atlOrigin=eyJpIjoiNWRkNTljNzYxNjVmNDY3MDlhMDU5Y2ZhYzA5YTRkZjUiLCJwIjoiZ2l0aHViLWNvbS1KU1cifQ