snoopysecurity / dvws-node

Damn Vulnerable Web Services is a vulnerable application with a web service and an API that can be used to learn about webservices/API related vulnerabilities.
GNU General Public License v3.0
442 stars 173 forks source link

[Snyk] Upgrade xml2js from 0.4.23 to 0.5.0 #47

Closed snoopysecurity closed 1 year ago

snoopysecurity commented 1 year ago

This PR was automatically created by Snyk using the credentials of a real user.


Snyk has created this PR to upgrade xml2js from 0.4.23 to 0.5.0.

:information_source: Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
- The recommended version is **1 version** ahead of your current version. - The recommended version was released **2 months ago**, on 2023-04-09. The recommended version fixes: Severity | Issue | PriorityScore (*) | Exploit Maturity | :-------------------------:|:-------------------------|-------------------------|:------------------------- | Prototype Pollution
[SNYK-JS-XML2JS-5414874](https://snyk.io/vuln/SNYK-JS-XML2JS-5414874) | **586/1000**
**Why?** Proof of Concept exploit, Has a fix available, CVSS 5.3 | Proof of Concept (*) Note that the real score may have changed since the PR was raised.
Release notes
Package name: xml2js
  • 0.5.0 - 2023-04-09

    Update package.json with latest PR

      </li>
      <li>
        <b>0.4.23</b> - 2019-12-19
      </li>
    </ul>
    from <a href="https://snyk.io/redirect/github/Leonidas-from-XIV/node-xml2js/releases">xml2js GitHub release notes</a>

Commit messages
Package name: xml2js
  • bd0f780 Bump dependency versions to fix security issues
  • 3a8d46e Update lockfile
  • 9f730bb Update package.json with latest PR
  • 50a492a Merge pull request #603 from autopulated/master
  • 7bc3c5d Merge pull request #598 from fnimick/master
  • f412a12 Merge pull request #635 from wisesimpson/patch-1
  • d318ce0 Update README.md
  • 581b19a use Object.create(null) to create all parsed objects (prevent prototype replacement)
  • a212950 Add documentation for `explicitCharkey` option
  • 1832e0b Merge pull request #512 from economia/master
  • 198063c Merge pull request #556 from Omega-Ariston/fix-issue544
  • 0d71785 Merge pull request #562 from Omega-Ariston/addDocExample
  • a44bad4 Update README.md
  • a3ae596 append example to README for issue #552
  • aad6dd6 fix issue554
  • fa32064 readme updated with default empty tag as function
  • f074644 cr fixes (will be squashed after another cr)
  • 19a4c2f Call function for emptyTag if specified
Compare

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.

For more information:

🧐 View latest project report

🛠 Adjust upgrade PR settings

🔕 Ignore this dependency or unsubscribe from future upgrade PRs