auth0 / auth0-authorization-extension

Auth0 Extension that adds authorization features to your account
https://auth0.com/docs/extensions/authorization-extension/v2
Other
82 stars 54 forks source link

[Snyk] Fix for 41 vulnerabilities #388

Open VictorGarridoAuth0 opened 2 months ago

VictorGarridoAuth0 commented 2 months ago

snyk-top-banner

Snyk has created this PR to fix 41 vulnerabilities in the npm dependencies of this project.

Snyk changed the following file(s):

Vulnerabilities that will be fixed with an upgrade:

Issue Score
high severity Server-side Request Forgery (SSRF)
SNYK-JS-IP-6240864
  751  
high severity Prototype Pollution
SNYK-JS-LODASH-567746
  731  
high severity Arbitrary Code Execution
SNYK-JS-HANDLEBARS-534478
  726  
high severity Remote Code Execution (RCE)
SNYK-JS-PACRESOLVER-1564857
  726  
high severity Server-side Request Forgery (SSRF)
SNYK-JS-NETMASK-1089716
  706  
high severity Server-side Request Forgery (SSRF)
SNYK-JS-NETMASK-6056519
  706  
critical severity Prototype Pollution
SNYK-JS-HANDLEBARS-534988
  704  
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-ANSIREGEX-1583908
  696  
high severity Prototype Pollution
SNYK-JS-LODASH-6139239
  696  
high severity Prototype Poisoning
SNYK-JS-QS-3153490
  696  
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-SEMVER-3247795
  696  
high severity Prototype Pollution
SNYK-JS-INI-1048974
  686  
high severity Prototype Pollution
SNYK-JS-LODASH-450202
  686  
high severity Prototype Pollution
SNYK-JS-LODASH-608086
  686  
high severity Prototype Pollution
SNYK-JS-LODASH-73638
  686  
high severity Prototype Pollution
SNYK-JS-Y18N-1021887
  686  
high severity Prototype Pollution
npm:deep-extend:20180409
  686  
high severity Code Injection
SNYK-JS-LODASH-1040724
  681  
high severity Remote Code Execution (RCE)
SNYK-JS-HANDLEBARS-1056767
  671  
medium severity Prototype Pollution
SNYK-JS-HANDLEBARS-567742
  646  
medium severity Server-Side Request Forgery (SSRF)
SNYK-JS-IP-7148531
  646  
medium severity Server-side Request Forgery (SSRF)
SNYK-JS-REQUEST-3361831
  646  
medium severity Prototype Pollution
SNYK-JS-TOUGHCOOKIE-5672873
  646  
high severity Prototype Pollution
SNYK-JS-JSONSCHEMA-1920922
  644  
medium severity Prototype Pollution
SNYK-JS-DOTPROP-543489
  636  
medium severity Prototype Pollution
npm:lodash:20180130
  636  
medium severity Man-in-the-Middle (MitM)
SNYK-JS-HTTPSPROXYAGENT-469131
  626  
high severity Prototype Pollution
SNYK-JS-AJV-584908
  619  
medium severity Prototype Pollution
SNYK-JS-HANDLEBARS-1279029
  601  
medium severity Prototype Pollution
SNYK-JS-MINIMIST-559764
  601  
high severity Denial of Service (DoS)
SNYK-JS-HANDLEBARS-480388
  589  
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-HOSTEDGITINFO-1088355
  586  
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-LODASH-1018905
  586  
high severity Prototype Pollution
SNYK-JS-HANDLEBARS-173692
  579  
high severity Prototype Pollution
SNYK-JS-HANDLEBARS-174183
  579  
high severity Prototype Pollution
SNYK-JS-HANDLEBARS-469063
  579  
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-LODASH-73639
  541  
medium severity Regular Expression Denial of Service (ReDoS)
npm:brace-expansion:20170302
  524  
low severity Prototype Pollution
SNYK-JS-MINIMIST-2429795
  506  
low severity Regular Expression Denial of Service (ReDoS)
npm:clean-css:20180306
  506  
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-MINIMATCH-3050818
  479  

[!IMPORTANT]

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report πŸ“œ Customise PR templates πŸ›  Adjust project settings πŸ“š Read about Snyk's upgrade logic


Learn how to fix vulnerabilities with free interactive lessons:

πŸ¦‰ Prototype Pollution πŸ¦‰ Regular Expression Denial of Service (ReDoS) πŸ¦‰ Remote Code Execution (RCE) πŸ¦‰ More lessons are available in Snyk Learn

semgrepcode-auth0[bot] commented 2 months ago

Semgrep found 1 ssc-d5d8f586-e6e9-42b3-8b5b-ab176a2efd4e finding:

Risk: npm 8.x before 8.11.0 is vulnerable to exposure of sensitive information to an unauthorized actor. The npm cli incorrectly ignores root-level .gitignore and .npmignore files when run in a workspace. Upgrade to npm 8.11.0.

Fix: Upgrade this library to at least version 8.11.0 at auth0-authorization-extension/package-lock.json:13586.

Reference(s): https://github.com/advisories/GHSA-hj9c-8jmm-8c52, CVE-2022-29244

Ignore this finding from ssc-d5d8f586-e6e9-42b3-8b5b-ab176a2efd4e.

semgrepcode-auth0[bot] commented 2 months ago

Semgrep found 1 ssc-d5d8f586-e6e9-42b3-8b5b-ab176a2efd4e finding:

Risk: npm 8.x before 8.11.0 is vulnerable to exposure of sensitive information to an unauthorized actor. The npm cli incorrectly ignores root-level .gitignore and .npmignore files when run in a workspace. Upgrade to npm 8.11.0.

Fix: Upgrade this library to at least version 8.11.0 at auth0-authorization-extension/package-lock.json:13586.

Reference(s): https://github.com/advisories/GHSA-hj9c-8jmm-8c52, CVE-2022-29244

Ignore this finding from ssc-d5d8f586-e6e9-42b3-8b5b-ab176a2efd4e.