[Snyk] Fix for 17 vulnerabilities
Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.
As this is a private repository, Snyk-bot does not have access. Therefore, this PR has been created automatically, but appears to have been created by a real user.
Changes included in this Merge Request
-
Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
- package.json
- package-lock.json
-
Adding or updating a Snyk policy (.snyk) file; this file is required in order to apply Snyk vulnerability patches. Find out more.
Vulnerabilities that will be fixed
With an upgrade:
Severity | Priority Score (*) | Issue | Breaking Change | Exploit Maturity |
---|---|---|---|---|
696/1000 Why? Proof of Concept exploit, Has a fix available, CVSS 7.5 |
Prototype Pollution SNYK-JS-ASYNC-2441827 |
No | Proof of Concept | |
630/1000 Why? Has a fix available, CVSS 8.1 |
Internal Property Tampering SNYK-JS-BSON-561052 |
No | No Known Exploit | |
506/1000 Why? Proof of Concept exploit, Has a fix available, CVSS 3.7 |
Prototype Pollution SNYK-JS-MINIMIST-2429795 |
Yes | Proof of Concept | |
601/1000 Why? Proof of Concept exploit, Has a fix available, CVSS 5.6 |
Prototype Pollution SNYK-JS-MINIMIST-559764 |
Yes | Proof of Concept | |
589/1000 Why? Has a fix available, CVSS 7.5 |
Regular Expression Denial of Service (ReDoS) SNYK-JS-MOCHA-561476 |
Yes | No Known Exploit | |
589/1000 Why? Has a fix available, CVSS 7.5 |
Denial of Service (DoS) SNYK-JS-MONGODB-473855 |
No | No Known Exploit | |
601/1000 Why? Proof of Concept exploit, Has a fix available, CVSS 5.6 |
Prototype Pollution SNYK-JS-MONGOOSE-1086688 |
No | Proof of Concept | |
671/1000 Why? Proof of Concept exploit, Has a fix available, CVSS 7 |
Prototype Pollution SNYK-JS-MONGOOSE-2961688 |
No | Proof of Concept | |
509/1000 Why? Has a fix available, CVSS 5.9 |
Information Exposure SNYK-JS-MONGOOSE-472486 |
No | No Known Exploit | |
601/1000 Why? Proof of Concept exploit, Has a fix available, CVSS 5.6 |
Prototype Pollution SNYK-JS-MPATH-1577289 |
No | Proof of Concept | |
579/1000 Why? Has a fix available, CVSS 7.3 |
Prototype Pollution SNYK-JS-MPATH-72672 |
No | No Known Exploit | |
686/1000 Why? Proof of Concept exploit, Has a fix available, CVSS 7.3 |
Prototype Pollution SNYK-JS-MQUERY-1050858 |
No | Proof of Concept | |
696/1000 Why? Proof of Concept exploit, Has a fix available, CVSS 7.5 |
Prototype Pollution SNYK-JS-MQUERY-1089718 |
No | Proof of Concept | |
539/1000 Why? Has a fix available, CVSS 6.5 |
Information Exposure SNYK-JS-NODEFETCH-2342118 |
No | No Known Exploit | |
520/1000 Why? Has a fix available, CVSS 5.9 |
Denial of Service SNYK-JS-NODEFETCH-674311 |
No | No Known Exploit |
(*) Note that the real score may have changed since the PR was raised.
Commit messages
Package name: mocha
The new version differs by 250 commits.- eb781e2 Release v6.2.3
- 10dbe94 update CHANGELOG for v6.2.3 [ci skip]
- 848d6fb security: update mkdirp, yargs, yargs-parser
- 843a322 6.2.2
- aec8b02 update CHANGELOG for v6.2.2 [ci skip]
- 7a8b95a npm audit fixes
- cebddf2 Improve reporter documentation for mocha in browser. (#4026)
- 3f7b987 uncaughtException: report more than one exception per test (#4033)
- ee82d38 modify alt text of image from Backers to Sponsors inside Sponsors section in Readme (#4046)
- e9c036c special-case parsing of "require" in unparseNodeArgs(); closes #4035 (#4063)
- 954cf0b Fix HTMLCollection iteration to make unhide function work as expected (#4051)
- 816dc27 uncaughtException: fix double EVENT_RUN_END events (#4025)
- 9650d3f add OpenJS Foundation logo to website (#4008)
- f04b81d Adopt the OpenJSF Code of Conduct (#3971)
- aca8895 Add link checking to docs build step (#3972)
- ef6c820 Release v6.2.1
- 9524978 updated CHANGELOG for v6.2.1 [ci skip]
- dfdb8b3 Update yargs to v13.3.0 (#3986)
- 18ad1c1 treat '--require esm' as Node option (#3983)
- fcffd5a Update yargs-unparser to v1.6.0 (#3984)
- ad4860e Remove extraGlobals() (#3970)
- b269ad0 Clarify effect of .skip() (#3947)
- 1e6cf3b Add Matomo to website (#3765)
- 91b3a54 fix style on mochajs.org (#3886)
Package name: mongoose
The new version differs by 250 commits.- ca7996b chore: release 5.13.15
- e75732a Merge pull request #12307 from Automattic/vkarpov15/fix-5x-build
- a1144dc test: run node 7 tests with upgraded npm re: #12297
- dfc4ad7 test: try upgrading npm for node v4 tests re: #12297
- b9e985c test: more strict @ types/node version
- 4d813fa test: fix @ types/node version in tests re: #12297
- 99b4189 Merge pull request #12297 from shubanker/issue/prototype-pollution-5.x-patch
- 5eb11dd made function non async
- 6a19731 fix(schema): disallow setting __proto__ when creating schema with dotted properties
- a2ec28d Merge pull request #11366 from laissonsilveira/5.x
- 05ce577 Fix broken link from findandmodify method deprecation
- d2b846f chore: release 5.13.14
- 69c1f6c docs(models): fix up nModified example for 5.x
- 4cfc4d6 fix(timestamps): avoid setting `createdAt` on documents that already exist but dont have createdAt
- a738440 chore: release 5.13.13
- 4d12a62 Merge pull request #10942 from jneal-afs/fix-query-set-ts-type
- c3463c4 Merge pull request #10916 from iovanom/gh-10902-v5
- ff5ddb5 fix: hardcode base 10 for nodeMajorVersion parseInt() call
- d205c4d make value optional
- c6fd7f7 Fix ts types for query set
- 22e9b3b [gh-10902 v5] Add node major version to utils
- 5468642 [gh-10902 v5] Emit end event in before close
- 271bc60 Merge pull request #10910 from lorand-horvath/patch-2
- b7ebeec Update mongodb driver to 3.7.3
Snyk patch:
With aSeverity | Priority Score (*) | Issue | Exploit Maturity |
---|---|---|---|
731/1000 Why? Proof of Concept exploit, Has a fix available, CVSS 8.2 |
Prototype Pollution SNYK-JS-LODASH-567746 |
Proof of Concept | |
579/1000 Why? Has a fix available, CVSS 7.3 |
Prototype Pollution npm:extend:20180424 |
No Known Exploit |
(*) Note that the real score may have changed since the PR was raised.
Check the changes in this Merge Request to ensure they won't cause issues with your project.
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
Learn how to fix vulnerabilities with free interactive lessons: