snoopysecurity / dvws-node

Damn Vulnerable Web Services is a vulnerable application with a web service and an API that can be used to learn about webservices/API related vulnerabilities.
GNU General Public License v3.0
442 stars 173 forks source link

[Snyk] Upgrade express-fileupload from 1.1.7-alpha.4 to 1.4.0 #43

Closed snoopysecurity closed 1 year ago

snoopysecurity commented 1 year ago

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to upgrade express-fileupload from 1.1.7-alpha.4 to 1.4.0.

:information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
- The recommended version is **8 versions** ahead of your current version. - The recommended version was released **a year ago**, on 2022-05-24. The recommended version fixes: Severity | Issue | PriorityScore (*) | Exploit Maturity | :-------------------------:|:-------------------------|-------------------------|:------------------------- | Denial of Service (DoS)
[SNYK-JS-DICER-2311764](https://snyk.io/vuln/SNYK-JS-DICER-2311764) | **546/1000**
**Why?** Mature exploit, CVSS 7.5 | Mature | Prototype Pollution
[SNYK-JS-EXPRESSFILEUPLOAD-595969](https://snyk.io/vuln/SNYK-JS-EXPRESSFILEUPLOAD-595969) | **546/1000**
**Why?** Mature exploit, CVSS 7.5 | Proof of Concept (*) Note that the real score may have changed since the PR was raised.
Release notes
Package name: express-fileupload
  • 1.4.0 - 2022-05-24

    What's Changed

    New Contributors

    Full Changelog: v1.3.1...v1.4.0

  • 1.3.1 - 2022-02-02

    Updates

    • Have promiseCallback make callbacks and promises behave the same (#302)
    • Fix prototype pollution in utilities.js (#301)
    • Switch to CircleCI (ddf5530)
    • End support for Node versions < 12 (ab3d252)
  • 1.3.0 - 2022-02-02

    1.3.0

      </li>
      <li>
        <b>1.2.1</b> - <a href="https://snyk.io/redirect/github/richardgirges/express-fileupload/releases/tag/v1.2.1">2021-01-11</a></br><h1>Updates:</h1>
    • (Fix) Stopped additional responses from being sent if a limit handler exists (#264)
    • Unhandled promise rejection warning (#257)
    • Changed example (#255)
    • Passing a Buffer body will pollute req.body when used along with processNested (#291)
      </li>
      <li>
        <b>1.2.0</b> - <a href="https://snyk.io/redirect/github/richardgirges/express-fileupload/releases/tag/1.2.0">2020-08-14</a></br><h1>Bug Fixes</h1>

    #241 Cleanup temporary files - @ nusu

      </li>
      <li>
        <b>1.1.10</b> - <a href="https://snyk.io/redirect/github/richardgirges/express-fileupload/releases/tag/1.1.10">2020-08-06</a></br><h1>Updates:</h1>

    Additional prototype-pollution security fix when using processNested (#239)

      </li>
      <li>
        <b>1.1.9</b> - <a href="https://snyk.io/redirect/github/richardgirges/express-fileupload/releases/tag/1.1.9">2020-07-31</a></br><h1>Updates:</h1>

    Second prototype pollution security vulnerability fix when using processNested (#236)

      </li>
      <li>
        <b>1.1.8</b> - <a href="https://snyk.io/redirect/github/richardgirges/express-fileupload/releases/tag/1.1.8">2020-07-29</a></br><h1>Updates:</h1>

    Fixed prototype pollution security vulnerability when using processNested (#236)

      </li>
      <li>
        <b>1.1.7-alpha.4</b> - <a href="https://snyk.io/redirect/github/richardgirges/express-fileupload/releases/tag/1.1.7-alpha.4">2020-07-16</a></br><h1>Updates:</h1>

    Fixes:

    • Fix empty file issue(#226)
    • Fix temp file write timing issue(#184). Thanks to @ somewind
    • Add empty file name check for parseFileName, issue(#187).
    • Write Timing Crash #192
    • when file.on('data') event timeouts, the case isn't handled properly #202
    • Do not create empty temporary files for empty file fields #191
      </li>
    </ul>
    from <a href="https://snyk.io/redirect/github/richardgirges/express-fileupload/releases">express-fileupload GitHub release notes</a>


Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

πŸ›  Adjust upgrade PR settings

πŸ”• Ignore this dependency or unsubscribe from future upgrade PRs