🔭 I'm currently working on an e-learning application.
fondation-defarsci's Introduction
fondation-defarsci's People
fondation-defarsci's Issues
[DepShield] (CVSS 7.4) Vulnerability due to usage of lodash.debounce:4.0.8
Vulnerabilities
DepShield reports that this application's usage of lodash.debounce:4.0.8 results in the following vulnerability(s):
- (CVSS 7.4) CWE-471: Modification of Assumed-Immutable Data (MAID)
- (CVSS 6.5) [CVE-2018-3721] lodash node module before 4.17.5 suffers from a Modification of Assumed-Immutabl...
Occurrences
lodash.debounce:4.0.8 is a transitive dependency introduced by the following direct dependency(s):
• vue2-leaflet-geosearch:1.0.6
└─ leaflet-geosearch:2.7.0
└─ lodash.debounce:4.0.8
This is an automated GitHub Issue created by Sonatype DepShield. Details on managing GitHub Apps, including DepShield, are available for personal and organization accounts. Please submit questions or feedback about DepShield to the Sonatype DepShield Community.
[DepShield] (CVSS 7.5) Vulnerability due to usage of postcss:7.0.21
Vulnerabilities
DepShield reports that this application's usage of postcss:7.0.21 results in the following vulnerability(s):
- (CVSS 7.5) CWE-400: Uncontrolled Resource Consumption ('Resource Exhaustion')
- (CVSS 5.3) [CVE-2021-23382] The package postcss before 8.2.13 are vulnerable to Regular Expression Denial of...
- (CVSS 5.3) [CVE-2021-23368] The package postcss from 7.0.0 and before 8.2.10 are vulnerable to Regular Expre...
Occurrences
postcss:7.0.21 is a transitive dependency introduced by the following direct dependency(s):
• resolve-url-loader:3.1.2
└─ postcss:7.0.21
This is an automated GitHub Issue created by Sonatype DepShield. Details on managing GitHub Apps, including DepShield, are available for personal and organization accounts. Please submit questions or feedback about DepShield to the Sonatype DepShield Community.
[DepShield] (CVSS 5.3) Vulnerability due to usage of kind-of:4.0.0
Vulnerabilities
DepShield reports that this application's usage of kind-of:4.0.0 results in the following vulnerability(s):
Occurrences
kind-of:4.0.0 is a transitive dependency introduced by the following direct dependency(s):
• laravel-mix:5.0.9
└─ chokidar:2.1.8
└─ braces:2.3.2
└─ snapdragon:0.8.2
└─ base:0.11.2
└─ cache-base:1.0.1
└─ has-value:1.0.0
└─ has-values:1.0.0
└─ kind-of:4.0.0
This is an automated GitHub Issue created by Sonatype DepShield. Details on managing GitHub Apps, including DepShield, are available for personal and organization accounts. Please submit questions or feedback about DepShield to the Sonatype DepShield Community.
[DepShield] (CVSS 7.5) Vulnerability due to usage of ssri:6.0.1
Vulnerabilities
DepShield reports that this application's usage of ssri:6.0.1 results in the following vulnerability(s):
- (CVSS 7.5) [CVE-2021-27290] ssri 5.2.2-8.0.0, fixed in 8.0.1, processes SRIs using a regular expression whic...
Occurrences
ssri:6.0.1 is a transitive dependency introduced by the following direct dependency(s):
• laravel-mix:5.0.9
└─ webpack:4.44.2
└─ terser-webpack-plugin:1.4.5
└─ cacache:12.0.4
└─ ssri:6.0.1
This is an automated GitHub Issue created by Sonatype DepShield. Details on managing GitHub Apps, including DepShield, are available for personal and organization accounts. Please submit questions or feedback about DepShield to the Sonatype DepShield Community.
[DepShield] (CVSS 7.4) Vulnerability due to usage of ini:1.3.5
Vulnerabilities
DepShield reports that this application's usage of ini:1.3.5 results in the following vulnerability(s):
Occurrences
ini:1.3.5 is a transitive dependency introduced by the following direct dependency(s):
• laravel-mix:5.0.9
└─ webpack-cli:3.3.12
└─ findup-sync:3.0.0
└─ resolve-dir:1.0.1
└─ global-modules:1.0.0
└─ global-prefix:1.0.2
└─ ini:1.3.5
└─ global-modules:2.0.0
└─ global-prefix:3.0.0
└─ ini:1.3.5
This is an automated GitHub Issue created by Sonatype DepShield. Details on managing GitHub Apps, including DepShield, are available for personal and organization accounts. Please submit questions or feedback about DepShield to the Sonatype DepShield Community.
[DepShield] (CVSS 7.5) Vulnerability due to usage of postcss:6.0.23
Vulnerabilities
DepShield reports that this application's usage of postcss:6.0.23 results in the following vulnerability(s):
- (CVSS 7.5) CWE-400: Uncontrolled Resource Consumption ('Resource Exhaustion')
- (CVSS 5.3) [CVE-2021-23382] The package postcss before 8.2.13 are vulnerable to Regular Expression Denial of...
Occurrences
postcss:6.0.23 is a transitive dependency introduced by the following direct dependency(s):
• laravel-mix:5.0.9
└─ css-loader:1.0.1
└─ postcss:6.0.23
└─ icss-utils:2.1.0
└─ postcss:6.0.23
└─ postcss-modules-extract-imports:1.2.1
└─ postcss:6.0.23
└─ postcss-modules-local-by-default:1.2.0
└─ postcss:6.0.23
└─ postcss-modules-scope:1.1.0
└─ postcss:6.0.23
└─ postcss-modules-values:1.3.0
└─ postcss:6.0.23
• tailwindcss:1.9.6
└─ postcss-functions:3.0.0
└─ postcss:6.0.23
This is an automated GitHub Issue created by Sonatype DepShield. Details on managing GitHub Apps, including DepShield, are available for personal and organization accounts. Please submit questions or feedback about DepShield to the Sonatype DepShield Community.
[DepShield] (CVSS 5.3) Vulnerability due to usage of ws:6.2.1
Vulnerabilities
DepShield reports that this application's usage of ws:6.2.1 results in the following vulnerability(s):
- (CVSS 5.3) [CVE-2021-32640] ws is an open source WebSocket client and server library for Node.js. A speciall...
Occurrences
ws:6.2.1 is a transitive dependency introduced by the following direct dependency(s):
• laravel-mix:5.0.9
└─ webpack-dev-server:3.11.0
└─ ws:6.2.1
This is an automated GitHub Issue created by Sonatype DepShield. Details on managing GitHub Apps, including DepShield, are available for personal and organization accounts. Please submit questions or feedback about DepShield to the Sonatype DepShield Community.
[DepShield] (CVSS 3.7) Vulnerability due to usage of elliptic:6.5.3
Vulnerabilities
DepShield reports that this application's usage of elliptic:6.5.3 results in the following vulnerability(s):
Occurrences
elliptic:6.5.3 is a transitive dependency introduced by the following direct dependency(s):
• laravel-mix:5.0.9
└─ webpack:4.44.2
└─ node-libs-browser:2.2.1
└─ crypto-browserify:3.12.0
└─ browserify-sign:4.2.1
└─ elliptic:6.5.3
└─ create-ecdh:4.0.4
└─ elliptic:6.5.3
This is an automated GitHub Issue created by Sonatype DepShield. Details on managing GitHub Apps, including DepShield, are available for personal and organization accounts. Please submit questions or feedback about DepShield to the Sonatype DepShield Community.
[DepShield] (CVSS 5.3) Vulnerability due to usage of browserslist:4.14.6
Vulnerabilities
DepShield reports that this application's usage of browserslist:4.14.6 results in the following vulnerability(s):
- (CVSS 5.3) [CVE-2021-23364] The package browserslist from 4.0.0 and before 4.16.5 are vulnerable to Regular ...
Occurrences
browserslist:4.14.6 is a transitive dependency introduced by the following direct dependency(s):
• laravel-mix:5.0.9
└─ @babel/preset-env:7.12.1
└─ @babel/helper-compilation-targets:7.12.5
└─ browserslist:4.14.6
└─ core-js-compat:3.7.0
└─ browserslist:4.14.6
└─ autoprefixer:9.8.6
└─ browserslist:4.14.6
└─ optimize-css-assets-webpack-plugin:5.0.4
└─ cssnano:4.1.10
└─ cssnano-preset-default:4.0.7
└─ postcss-colormin:4.0.3
└─ browserslist:4.14.6
└─ postcss-merge-longhand:4.0.11
└─ stylehacks:4.0.3
└─ browserslist:4.14.6
└─ postcss-merge-rules:4.0.3
└─ browserslist:4.14.6
└─ caniuse-api:3.0.0
└─ browserslist:4.14.6
└─ postcss-minify-params:4.0.2
└─ browserslist:4.14.6
└─ postcss-normalize-unicode:4.0.1
└─ browserslist:4.14.6
└─ postcss-reduce-initial:4.0.3
└─ browserslist:4.14.6
• tailwindcss:1.9.6
└─ browserslist:4.14.6
This is an automated GitHub Issue created by Sonatype DepShield. Details on managing GitHub Apps, including DepShield, are available for personal and organization accounts. Please submit questions or feedback about DepShield to the Sonatype DepShield Community.
[DepShield] (CVSS 7.5) Vulnerability due to usage of express:4.17.1
Vulnerabilities
DepShield reports that this application's usage of express:4.17.1 results in the following vulnerability(s):
Occurrences
express:4.17.1 is a transitive dependency introduced by the following direct dependency(s):
• laravel-mix:5.0.9
└─ webpack-dev-server:3.11.0
└─ express:4.17.1
This is an automated GitHub Issue created by Sonatype DepShield. Details on managing GitHub Apps, including DepShield, are available for personal and organization accounts. Please submit questions or feedback about DepShield to the Sonatype DepShield Community.
[DepShield] (CVSS 7.5) Vulnerability due to usage of glob-parent:3.1.0
Vulnerabilities
DepShield reports that this application's usage of glob-parent:3.1.0 results in the following vulnerability(s):
Occurrences
glob-parent:3.1.0 is a transitive dependency introduced by the following direct dependency(s):
• laravel-mix:5.0.9
└─ chokidar:2.1.8
└─ glob-parent:3.1.0
└─ imagemin:6.1.0
└─ globby:8.0.2
└─ fast-glob:2.2.7
└─ glob-parent:3.1.0
This is an automated GitHub Issue created by Sonatype DepShield. Details on managing GitHub Apps, including DepShield, are available for personal and organization accounts. Please submit questions or feedback about DepShield to the Sonatype DepShield Community.
[DepShield] (CVSS 7.4) Vulnerability due to usage of lodash.memoize:4.1.2
Vulnerabilities
DepShield reports that this application's usage of lodash.memoize:4.1.2 results in the following vulnerability(s):
- (CVSS 7.4) CWE-471: Modification of Assumed-Immutable Data (MAID)
- (CVSS 6.5) [CVE-2018-3721] lodash node module before 4.17.5 suffers from a Modification of Assumed-Immutabl...
Occurrences
lodash.memoize:4.1.2 is a transitive dependency introduced by the following direct dependency(s):
• laravel-mix:5.0.9
└─ optimize-css-assets-webpack-plugin:5.0.4
└─ cssnano:4.1.10
└─ cssnano-preset-default:4.0.7
└─ postcss-merge-rules:4.0.3
└─ caniuse-api:3.0.0
└─ lodash.memoize:4.1.2
This is an automated GitHub Issue created by Sonatype DepShield. Details on managing GitHub Apps, including DepShield, are available for personal and organization accounts. Please submit questions or feedback about DepShield to the Sonatype DepShield Community.
[DepShield] (CVSS 7.5) Vulnerability due to usage of path-parse:1.0.6
Vulnerabilities
DepShield reports that this application's usage of path-parse:1.0.6 results in the following vulnerability(s):
- (CVSS 7.5) [CVE-2021-23343] All versions of package path-parse are vulnerable to Regular Expression Denial o...
Occurrences
path-parse:1.0.6 is a transitive dependency introduced by the following direct dependency(s):
• postcss-import:12.0.1
└─ resolve:1.18.1
└─ path-parse:1.0.6
This is an automated GitHub Issue created by Sonatype DepShield. Details on managing GitHub Apps, including DepShield, are available for personal and organization accounts. Please submit questions or feedback about DepShield to the Sonatype DepShield Community.
[DepShield] (CVSS 7.5) Vulnerability due to usage of ansi-html:0.0.7
Vulnerabilities
DepShield reports that this application's usage of ansi-html:0.0.7 results in the following vulnerability(s):
- (CVSS 7.5) [CVE-2021-23424] This affects all versions of package ansi-html. If an attacker provides a malici...
Occurrences
ansi-html:0.0.7 is a transitive dependency introduced by the following direct dependency(s):
• laravel-mix:5.0.9
└─ webpack-dev-server:3.11.0
└─ ansi-html:0.0.7
This is an automated GitHub Issue created by Sonatype DepShield. Details on managing GitHub Apps, including DepShield, are available for personal and organization accounts. Please submit questions or feedback about DepShield to the Sonatype DepShield Community.
[DepShield] (CVSS 7.4) Vulnerability due to usage of lodash.toarray:4.4.0
Vulnerabilities
DepShield reports that this application's usage of lodash.toarray:4.4.0 results in the following vulnerability(s):
Occurrences
lodash.toarray:4.4.0 is a transitive dependency introduced by the following direct dependency(s):
• tailwindcss:1.9.6
└─ node-emoji:1.10.0
└─ lodash.toarray:4.4.0
This is an automated GitHub Issue created by Sonatype DepShield. Details on managing GitHub Apps, including DepShield, are available for personal and organization accounts. Please submit questions or feedback about DepShield to the Sonatype DepShield Community.
[DepShield] (CVSS 7.5) Vulnerability due to usage of ssri:7.1.0
Vulnerabilities
DepShield reports that this application's usage of ssri:7.1.0 results in the following vulnerability(s):
- (CVSS 7.5) [CVE-2021-27290] ssri 5.2.2-8.0.0, fixed in 8.0.1, processes SRIs using a regular expression whic...
Occurrences
ssri:7.1.0 is a transitive dependency introduced by the following direct dependency(s):
• laravel-mix:5.0.9
└─ terser-webpack-plugin:2.3.8
└─ cacache:13.0.1
└─ ssri:7.1.0
This is an automated GitHub Issue created by Sonatype DepShield. Details on managing GitHub Apps, including DepShield, are available for personal and organization accounts. Please submit questions or feedback about DepShield to the Sonatype DepShield Community.
[DepShield] (CVSS 5.3) Vulnerability due to usage of kind-of:5.1.0
Vulnerabilities
DepShield reports that this application's usage of kind-of:5.1.0 results in the following vulnerability(s):
Occurrences
kind-of:5.1.0 is a transitive dependency introduced by the following direct dependency(s):
• laravel-mix:5.0.9
└─ chokidar:2.1.8
└─ braces:2.3.2
└─ snapdragon:0.8.2
└─ define-property:0.2.5
└─ is-descriptor:0.1.6
└─ kind-of:5.1.0
This is an automated GitHub Issue created by Sonatype DepShield. Details on managing GitHub Apps, including DepShield, are available for personal and organization accounts. Please submit questions or feedback about DepShield to the Sonatype DepShield Community.
[DepShield] (CVSS 7.5) Vulnerability due to usage of debug:2.6.9
Vulnerabilities
DepShield reports that this application's usage of debug:2.6.9 results in the following vulnerability(s):
Occurrences
debug:2.6.9 is a transitive dependency introduced by the following direct dependency(s):
• laravel-mix:5.0.9
└─ chokidar:2.1.8
└─ braces:2.3.2
└─ snapdragon:0.8.2
└─ debug:2.6.9
└─ webpack:4.44.2
└─ micromatch:3.1.10
└─ extglob:2.0.4
└─ expand-brackets:2.1.4
└─ debug:2.6.9
└─ webpack-dev-server:3.11.0
└─ compression:1.7.4
└─ debug:2.6.9
└─ express:4.17.1
└─ body-parser:1.19.0
└─ debug:2.6.9
└─ debug:2.6.9
└─ finalhandler:1.1.2
└─ debug:2.6.9
└─ send:0.17.1
└─ debug:2.6.9
└─ serve-index:1.9.1
└─ debug:2.6.9
This is an automated GitHub Issue created by Sonatype DepShield. Details on managing GitHub Apps, including DepShield, are available for personal and organization accounts. Please submit questions or feedback about DepShield to the Sonatype DepShield Community.
[DepShield] (CVSS 7.4) Vulnerability due to usage of lodash.uniq:4.5.0
Vulnerabilities
DepShield reports that this application's usage of lodash.uniq:4.5.0 results in the following vulnerability(s):
- (CVSS 7.4) CWE-471: Modification of Assumed-Immutable Data (MAID)
- (CVSS 6.5) [CVE-2018-3721] lodash node module before 4.17.5 suffers from a Modification of Assumed-Immutabl...
Occurrences
lodash.uniq:4.5.0 is a transitive dependency introduced by the following direct dependency(s):
• laravel-mix:5.0.9
└─ optimize-css-assets-webpack-plugin:5.0.4
└─ cssnano:4.1.10
└─ cssnano-preset-default:4.0.7
└─ postcss-merge-rules:4.0.3
└─ caniuse-api:3.0.0
└─ lodash.uniq:4.5.0
This is an automated GitHub Issue created by Sonatype DepShield. Details on managing GitHub Apps, including DepShield, are available for personal and organization accounts. Please submit questions or feedback about DepShield to the Sonatype DepShield Community.
[DepShield] (CVSS 5.3) Vulnerability due to usage of kind-of:3.2.2
Vulnerabilities
DepShield reports that this application's usage of kind-of:3.2.2 results in the following vulnerability(s):
Occurrences
kind-of:3.2.2 is a transitive dependency introduced by the following direct dependency(s):
• laravel-mix:5.0.9
└─ chokidar:2.1.8
└─ braces:2.3.2
└─ fill-range:4.0.0
└─ is-number:3.0.0
└─ kind-of:3.2.2
└─ snapdragon:0.8.2
└─ base:0.11.2
└─ cache-base:1.0.1
└─ to-object-path:0.3.0
└─ kind-of:3.2.2
└─ class-utils:0.3.6
└─ static-extend:0.1.2
└─ object-copy:0.1.0
└─ kind-of:3.2.2
└─ define-property:0.2.5
└─ is-descriptor:0.1.6
└─ is-accessor-descriptor:0.1.6
└─ kind-of:3.2.2
└─ is-data-descriptor:0.1.4
└─ kind-of:3.2.2
└─ snapdragon-node:2.1.1
└─ snapdragon-util:3.0.1
└─ kind-of:3.2.2
This is an automated GitHub Issue created by Sonatype DepShield. Details on managing GitHub Apps, including DepShield, are available for personal and organization accounts. Please submit questions or feedback about DepShield to the Sonatype DepShield Community.
[DepShield] (CVSS 7.5) Vulnerability due to usage of http-proxy:1.18.1
Vulnerabilities
DepShield reports that this application's usage of http-proxy:1.18.1 results in the following vulnerability(s):
Occurrences
http-proxy:1.18.1 is a transitive dependency introduced by the following direct dependency(s):
• laravel-mix:5.0.9
└─ webpack-dev-server:3.11.0
└─ http-proxy-middleware:0.19.1
└─ http-proxy:1.18.1
This is an automated GitHub Issue created by Sonatype DepShield. Details on managing GitHub Apps, including DepShield, are available for personal and organization accounts. Please submit questions or feedback about DepShield to the Sonatype DepShield Community.
[DepShield] (CVSS 8.2) Vulnerability due to usage of y18n:4.0.0
Vulnerabilities
DepShield reports that this application's usage of y18n:4.0.0 results in the following vulnerability(s):
- (CVSS 8.2) CWE-20: Improper Input Validation
Occurrences
y18n:4.0.0 is a transitive dependency introduced by the following direct dependency(s):
• laravel-mix:5.0.9
└─ webpack:4.44.2
└─ terser-webpack-plugin:1.4.5
└─ cacache:12.0.4
└─ y18n:4.0.0
└─ webpack-cli:3.3.12
└─ yargs:13.3.2
└─ y18n:4.0.0
└─ webpack-dev-server:3.11.0
└─ yargs:13.3.2
└─ y18n:4.0.0
└─ yargs:15.4.1
└─ y18n:4.0.0
This is an automated GitHub Issue created by Sonatype DepShield. Details on managing GitHub Apps, including DepShield, are available for personal and organization accounts. Please submit questions or feedback about DepShield to the Sonatype DepShield Community.
[DepShield] (CVSS 9.8) Vulnerability due to usage of lodash:4.17.20
Vulnerabilities
DepShield reports that this application's usage of lodash:4.17.20 results in the following vulnerability(s):
- (CVSS 9.8) CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection')
- (CVSS 7.2) [CVE-2021-23337] Lodash versions prior to 4.17.21 are vulnerable to Command Injection via the tem...
- (CVSS 5.3) [CVE-2020-28500] All versions of package lodash; all versions of package org.fujion.webjars:lodas...
Occurrences
lodash:4.17.20 is a transitive dependency introduced by the following direct dependency(s):
• @tailwindcss/ui:0.6.2
└─ @tailwindcss/custom-forms:0.2.1
└─ lodash:4.17.20
• laravel-mix:5.0.9
└─ @babel/core:7.12.3
└─ @babel/helper-module-transforms:7.12.1
└─ lodash:4.17.20
└─ @babel/traverse:7.12.5
└─ lodash:4.17.20
└─ @babel/types:7.12.6
└─ lodash:4.17.20
└─ lodash:4.17.20
└─ @babel/preset-env:7.12.1
└─ @babel/plugin-transform-classes:7.12.1
└─ @babel/helper-define-map:7.10.5
└─ lodash:4.17.20
└─ @babel/plugin-transform-sticky-regex:7.12.1
└─ @babel/helper-regex:7.10.5
└─ lodash:4.17.20
└─ css-loader:1.0.1
└─ lodash:4.17.20
└─ extract-text-webpack-plugin:4.0.0-beta.0
└─ async:2.6.3
└─ lodash:4.17.20
└─ lodash:4.17.20
└─ optimize-css-assets-webpack-plugin:5.0.4
└─ last-call-webpack-plugin:3.0.0
└─ lodash:4.17.20
└─ webpack-dev-server:3.11.0
└─ http-proxy-middleware:0.19.1
└─ lodash:4.17.20
└─ webpack-merge:4.2.2
└─ lodash:4.17.20
• tailwindcss:1.9.6
└─ lodash:4.17.20
This is an automated GitHub Issue created by Sonatype DepShield. Details on managing GitHub Apps, including DepShield, are available for personal and organization accounts. Please submit questions or feedback about DepShield to the Sonatype DepShield Community.
[DepShield] (CVSS 7.5) Vulnerability due to usage of postcss:7.0.35
Vulnerabilities
DepShield reports that this application's usage of postcss:7.0.35 results in the following vulnerability(s):
- (CVSS 7.5) CWE-400: Uncontrolled Resource Consumption ('Resource Exhaustion')
- (CVSS 5.3) [CVE-2021-23382] The package postcss before 8.2.13 are vulnerable to Regular Expression Denial of...
- (CVSS 5.3) [CVE-2021-23368] The package postcss from 7.0.0 and before 8.2.10 are vulnerable to Regular Expre...
Occurrences
postcss:7.0.35 is a transitive dependency introduced by the following direct dependency(s):
• laravel-mix:5.0.9
└─ autoprefixer:9.8.6
└─ postcss:7.0.35
└─ optimize-css-assets-webpack-plugin:5.0.4
└─ cssnano:4.1.10
└─ cssnano-preset-default:4.0.7
└─ css-declaration-sorter:4.0.1
└─ postcss:7.0.35
└─ cssnano-util-raw-cache:4.0.1
└─ postcss:7.0.35
└─ postcss:7.0.35
└─ postcss-calc:7.0.5
└─ postcss:7.0.35
└─ postcss-colormin:4.0.3
└─ postcss:7.0.35
└─ postcss-convert-values:4.0.1
└─ postcss:7.0.35
└─ postcss-discard-comments:4.0.2
└─ postcss:7.0.35
└─ postcss-discard-duplicates:4.0.2
└─ postcss:7.0.35
└─ postcss-discard-empty:4.0.1
└─ postcss:7.0.35
└─ postcss-discard-overridden:4.0.1
└─ postcss:7.0.35
└─ postcss-merge-longhand:4.0.11
└─ postcss:7.0.35
└─ stylehacks:4.0.3
└─ postcss:7.0.35
└─ postcss-merge-rules:4.0.3
└─ postcss:7.0.35
└─ postcss-minify-font-values:4.0.2
└─ postcss:7.0.35
└─ postcss-minify-gradients:4.0.2
└─ postcss:7.0.35
└─ postcss-minify-params:4.0.2
└─ postcss:7.0.35
└─ postcss-minify-selectors:4.0.2
└─ postcss:7.0.35
└─ postcss-normalize-charset:4.0.1
└─ postcss:7.0.35
└─ postcss-normalize-display-values:4.0.2
└─ postcss:7.0.35
└─ postcss-normalize-positions:4.0.2
└─ postcss:7.0.35
└─ postcss-normalize-repeat-style:4.0.2
└─ postcss:7.0.35
└─ postcss-normalize-string:4.0.2
└─ postcss:7.0.35
└─ postcss-normalize-timing-functions:4.0.2
└─ postcss:7.0.35
└─ postcss-normalize-unicode:4.0.1
└─ postcss:7.0.35
└─ postcss-normalize-url:4.0.1
└─ postcss:7.0.35
└─ postcss-normalize-whitespace:4.0.2
└─ postcss:7.0.35
└─ postcss-ordered-values:4.1.2
└─ postcss:7.0.35
└─ postcss-reduce-initial:4.0.3
└─ postcss:7.0.35
└─ postcss-reduce-transforms:4.0.2
└─ postcss:7.0.35
└─ postcss-svgo:4.0.2
└─ postcss:7.0.35
└─ postcss-unique-selectors:4.0.1
└─ postcss:7.0.35
└─ postcss:7.0.35
└─ postcss-loader:3.0.0
└─ postcss:7.0.35
└─ vue-loader:15.9.5
└─ @vue/component-compiler-utils:3.2.0
└─ postcss:7.0.35
• postcss-import:12.0.1
└─ postcss:7.0.35
• tailwindcss:1.9.6
└─ postcss:7.0.35
└─ postcss-js:2.0.3
└─ postcss:7.0.35
└─ postcss-nested:4.2.3
└─ postcss:7.0.35
This is an automated GitHub Issue created by Sonatype DepShield. Details on managing GitHub Apps, including DepShield, are available for personal and organization accounts. Please submit questions or feedback about DepShield to the Sonatype DepShield Community.
[DepShield] (CVSS 7.5) Vulnerability due to usage of glob-parent:5.1.1
Vulnerabilities
DepShield reports that this application's usage of glob-parent:5.1.1 results in the following vulnerability(s):
Occurrences
glob-parent:5.1.1 is a transitive dependency introduced by the following direct dependency(s):
• laravel-mix:5.0.9
└─ webpack:4.44.2
└─ watchpack:1.7.4
└─ chokidar:3.4.3
└─ glob-parent:5.1.1
This is an automated GitHub Issue created by Sonatype DepShield. Details on managing GitHub Apps, including DepShield, are available for personal and organization accounts. Please submit questions or feedback about DepShield to the Sonatype DepShield Community.
[DepShield] (CVSS 7.5) Vulnerability due to usage of axios:0.19.2
Vulnerabilities
DepShield reports that this application's usage of axios:0.19.2 results in the following vulnerability(s):
- (CVSS 7.5) [CVE-2021-3749] axios is vulnerable to Inefficient Regular Expression Complexity
- (CVSS 7.3) CWE-918: Server-Side Request Forgery (SSRF)
- (CVSS 5.9) [CVE-2020-28168] Axios NPM package 0.21.0 contains a Server-Side Request Forgery (SSRF) vulnerabi...
Occurrences
axios:0.19.2 is a transitive dependency introduced by the following direct dependency(s):
• @inertiajs/inertia:0.3.6
└─ axios:0.19.2
• laravel-jetstream:0.0.3
└─ @inertiajs/inertia:0.1.9
└─ axios:0.19.2
This is an automated GitHub Issue created by Sonatype DepShield. Details on managing GitHub Apps, including DepShield, are available for personal and organization accounts. Please submit questions or feedback about DepShield to the Sonatype DepShield Community.
[DepShield] (CVSS 7.5) Vulnerability due to usage of q:1.5.1
Vulnerabilities
DepShield reports that this application's usage of q:1.5.1 results in the following vulnerability(s):
Occurrences
q:1.5.1 is a transitive dependency introduced by the following direct dependency(s):
• laravel-mix:5.0.9
└─ optimize-css-assets-webpack-plugin:5.0.4
└─ cssnano:4.1.10
└─ cssnano-preset-default:4.0.7
└─ postcss-svgo:4.0.2
└─ svgo:1.3.2
└─ coa:2.0.2
└─ q:1.5.1
This is an automated GitHub Issue created by Sonatype DepShield. Details on managing GitHub Apps, including DepShield, are available for personal and organization accounts. Please submit questions or feedback about DepShield to the Sonatype DepShield Community.
[DepShield] (CVSS 7.5) Vulnerability due to usage of postcss:7.0.32
Vulnerabilities
DepShield reports that this application's usage of postcss:7.0.32 results in the following vulnerability(s):
- (CVSS 7.5) CWE-400: Uncontrolled Resource Consumption ('Resource Exhaustion')
- (CVSS 5.3) [CVE-2021-23382] The package postcss before 8.2.13 are vulnerable to Regular Expression Denial of...
- (CVSS 5.3) [CVE-2021-23368] The package postcss from 7.0.0 and before 8.2.10 are vulnerable to Regular Expre...
Occurrences
postcss:7.0.32 is a transitive dependency introduced by the following direct dependency(s):
• tailwindcss:1.9.6
└─ @fullhuman/postcss-purgecss:2.3.0
└─ postcss:7.0.32
└─ purgecss:2.3.0
└─ postcss:7.0.32
This is an automated GitHub Issue created by Sonatype DepShield. Details on managing GitHub Apps, including DepShield, are available for personal and organization accounts. Please submit questions or feedback about DepShield to the Sonatype DepShield Community.
[DepShield] (CVSS 7.5) Vulnerability due to usage of url-parse:1.4.7
Vulnerabilities
DepShield reports that this application's usage of url-parse:1.4.7 results in the following vulnerability(s):
- (CVSS 7.5) CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
- (CVSS 6.1) [CVE-2021-3664] url-parse is vulnerable to URL Redirection to Untrusted Site
- (CVSS 5.3) [CVE-2021-27515] url-parse before 1.5.0 mishandles certain uses of backslash such as http:/ and ...
Occurrences
url-parse:1.4.7 is a transitive dependency introduced by the following direct dependency(s):
• laravel-mix:5.0.9
└─ webpack-dev-server:3.11.0
└─ sockjs-client:1.4.0
└─ eventsource:1.0.7
└─ original:1.0.2
└─ url-parse:1.4.7
└─ url-parse:1.4.7
This is an automated GitHub Issue created by Sonatype DepShield. Details on managing GitHub Apps, including DepShield, are available for personal and organization accounts. Please submit questions or feedback about DepShield to the Sonatype DepShield Community.
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.