ministryofjustice / cla_frontend

CLA Front End
http://ministryofjustice.github.io/cla_docs/
MIT License
3 stars 4 forks source link

[Snyk] Fix for 36 vulnerabilities #977

Open Pheonnexx opened 2 months ago

Pheonnexx commented 2 months ago

snyk-top-banner

Snyk has created this PR to fix 36 vulnerabilities in the npm dependencies of this project.

Snyk changed the following file(s):

Vulnerabilities that will be fixed with an upgrade:

Issue Score
critical severity Improper Verification of Cryptographic Signature
SNYK-JS-ELLIPTIC-7577916
  776  
critical severity Improper Verification of Cryptographic Signature
SNYK-JS-ELLIPTIC-7577917
  776  
critical severity Improper Verification of Cryptographic Signature
SNYK-JS-ELLIPTIC-7577918
  776  
high severity Arbitrary Code Execution
SNYK-JS-HANDLEBARS-534478
  726  
medium severity Cross-site Scripting (XSS)
SNYK-JS-JQUERY-567880
  711  
high severity Cryptographic Issues
SNYK-JS-ELLIPTIC-571484
  706  
critical severity Prototype Pollution
SNYK-JS-HANDLEBARS-534988
  704  
medium severity Cross-site Scripting (XSS)
SNYK-JS-JQUERY-565129
  701  
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-MOMENT-2944238
  696  
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-SEMVER-3247795
  696  
high severity Prototype Pollution
SNYK-JS-CACHEDPATHRELATIVE-2342653
  686  
high severity Remote Code Execution (RCE)
SNYK-JS-HANDLEBARS-1056767
  671  
medium severity Prototype Pollution
SNYK-JS-HANDLEBARS-567742
  646  
medium severity Denial of Service (DoS)
SNYK-JS-HTTPPROXY-569139
  646  
high severity Improper minification of non-boolean comparisons
npm:uglify-js:20150824
  629  
high severity Remote Code Execution (RCE)
SNYK-JS-SHELLQUOTE-1766506
  619  
medium severity Prototype Pollution
SNYK-JS-HANDLEBARS-1279029
  601  
medium severity Prototype Pollution
SNYK-JS-JQUERY-174006
  601  
medium severity Prototype Pollution
SNYK-JS-MINIMIST-559764
  601  
high severity Improper Verification of Cryptographic Signature
SNYK-JS-BROWSERIFYSIGN-6037026
  589  
high severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-MINIMATCH-1019388
  589  
high severity Directory Traversal
SNYK-JS-MOMENT-2440688
  589  
high severity Regular Expression Denial of Service (ReDoS)
npm:minimatch:20160620
  589  
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-HOSTEDGITINFO-1088355
  586  
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-PATHPARSE-1077067
  586  
high severity Prototype Pollution
SNYK-JS-CACHEDPATHRELATIVE-72573
  579  
high severity Prototype Pollution
SNYK-JS-HANDLEBARS-173692
  579  
high severity Prototype Pollution
SNYK-JS-HANDLEBARS-469063
  579  
medium severity Cryptographic Issues
SNYK-JS-ELLIPTIC-1064899
  554  
medium severity Timing Attack
SNYK-JS-ELLIPTIC-511941
  509  
low severity Prototype Pollution
SNYK-JS-MINIMIST-2429795
  506  
medium severity Cross-site Scripting (XSS)
npm:jquery:20150627
  484  
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-MINIMATCH-3050818
  479  
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-UGLIFYJS-1727251
  479  
medium severity Cross-site Scripting (XSS)
npm:handlebars:20151207
  479  
medium severity Regular Expression Denial of Service (ReDoS)
npm:uglify-js:20151024
  479  

[!IMPORTANT]

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information: 🧐 View latest project report 📜 Customise PR templates 🛠 Adjust project settings 📚 Read about Snyk's upgrade logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Prototype Pollution 🦉 Cryptographic Issues 🦉 Remote Code Execution (RCE) 🦉 More lessons are available in Snyk Learn

sonarcloud[bot] commented 2 months ago

Quality Gate Passed Quality Gate passed

Issues
0 New issues
0 Accepted issues

Measures
0 Security Hotspots
0.0% Coverage on New Code
0.0% Duplication on New Code

See analysis details on SonarCloud