Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Snyk] Security upgrade @sectester/reporter from 0.16.5 to 0.29.0 #141

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

TheRedHatter
Copy link
Owner

This PR was automatically created by Snyk using the credentials of a real user.


![snyk-top-banner](https://github.com/andygongea/OWASP-Benchmark/assets/818805/c518c423-16fe-447e-b67f-ad5a49b5d123)

Snyk has created this PR to fix 2 vulnerabilities in the npm dependencies of this project.

Snyk changed the following file(s):

  • package.json
  • package-lock.json

Vulnerabilities that will be fixed with an upgrade:

Issue Score
high severity Cross-site Request Forgery (CSRF)
SNYK-JS-AXIOS-6032459
  676  
medium severity Regular Expression Denial of Service (ReDoS)
SNYK-JS-AXIOS-6124857
  586  

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉 Cross-site Request Forgery (CSRF)
🦉 Regular Expression Denial of Service (ReDoS)

Copy link

sonarcloud bot commented Jun 20, 2024

@@ -40,7 +40,7 @@
"@sectester/bus": "^0.16.5",
"@sectester/core": "^0.16.5",
"@sectester/repeater": "^0.16.5",
"@sectester/reporter": "^0.16.5",
"@sectester/reporter": "^0.29.0",
"@sectester/runner": "^0.16.5",

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@sectester/runner 0.16.5 / package.json

Total vulnerabilities: 6

Critical: 2 High: 3 Medium: 1 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2023-26136 CRITICAL CRITICAL 9.8 - Open
CVE-2023-42282 CRITICAL CRITICAL 9.8 - Open
CVE-2022-25883 HIGH HIGH 7.5 - Open
CVE-2024-29415 HIGH HIGH - - Open
CVE-2024-37890 HIGH HIGH 7.5 - Open
CVE-2024-28849 MEDIUM MEDIUM 6.5 - Open

@@ -40,7 +40,7 @@
"@sectester/bus": "^0.16.5",
"@sectester/core": "^0.16.5",
"@sectester/repeater": "^0.16.5",

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@sectester/repeater 0.16.5 / package.json

Total vulnerabilities: 6

Critical: 2 High: 3 Medium: 1 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2023-26136 CRITICAL CRITICAL 9.8 - Open
CVE-2023-42282 CRITICAL CRITICAL 9.8 - Open
CVE-2022-25883 HIGH HIGH 7.5 - Open
CVE-2024-29415 HIGH HIGH - - Open
CVE-2024-37890 HIGH HIGH 7.5 - Open
CVE-2024-28849 MEDIUM MEDIUM 6.5 - Open

@@ -40,7 +40,7 @@
"@sectester/bus": "^0.16.5",
"@sectester/core": "^0.16.5",
"@sectester/repeater": "^0.16.5",
"@sectester/reporter": "^0.16.5",
"@sectester/reporter": "^0.29.0",
"@sectester/runner": "^0.16.5",
"@sectester/scan": "^0.16.5",

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@sectester/scan 0.16.5 / package.json

Total vulnerabilities: 1

Critical: 0 High: 0 Medium: 1 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2024-28849 MEDIUM MEDIUM 6.5 - Open

@@ -40,7 +40,7 @@
"@sectester/bus": "^0.16.5",
"@sectester/core": "^0.16.5",
"@sectester/repeater": "^0.16.5",
"@sectester/reporter": "^0.16.5",
"@sectester/reporter": "^0.29.0",

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@sectester/reporter 0.29.0 / package.json

Total vulnerabilities: 1

Critical: 0 High: 0 Medium: 1 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2024-28849 MEDIUM MEDIUM 6.5 - Open

@@ -40,7 +40,7 @@
"@sectester/bus": "^0.16.5",

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@sectester/bus 0.16.5 / package.json

Total vulnerabilities: 1

Critical: 0 High: 0 Medium: 1 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2024-28849 MEDIUM MEDIUM 6.5 - Open

@@ -40,7 +40,7 @@
"@sectester/bus": "^0.16.5",
"@sectester/core": "^0.16.5",
"@sectester/repeater": "^0.16.5",
"@sectester/reporter": "^0.16.5",
"@sectester/reporter": "^0.29.0",

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

axios 0.21.4 / package.json

Total vulnerabilities: 1

Critical: 0 High: 0 Medium: 1 Low: 0
Vulnerability IDSeverityCVSSFixed inStatus
CVE-2024-28849 MEDIUM MEDIUM 6.5 - Open

@TheRedHatter
Copy link
Owner Author

Logo
Checkmarx One – Scan Summary & Details63a52e6b-cfce-40d8-ab4f-23acf31466ee

New Issues

Severity Issue Source File / Package Checkmarx Insight
HIGH CVE-2024-37890 Npm-ws-8.12.0 Vulnerable Package
HIGH CVE-2024-37890 Npm-ws-7.5.9 Vulnerable Package
HIGH CVE-2024-37890 Npm-ws-8.12.1 Vulnerable Package
HIGH CVE-2024-37890 Npm-ws-6.2.2 Vulnerable Package
MEDIUM Client_HTML5_Store_Sensitive_data_In_Web_Storage /public/src/pages/main/Userprofile.tsx: 50 Attack Vector
MEDIUM Client_HTML5_Store_Sensitive_data_In_Web_Storage /public/src/pages/auth/LoginNew/PasswordCheck.tsx: 70 Attack Vector
MEDIUM Client_HTML5_Store_Sensitive_data_In_Web_Storage /public/src/pages/auth/Login/Login.tsx: 89 Attack Vector
MEDIUM Client_HTML5_Store_Sensitive_data_In_Web_Storage /public/src/pages/main/Userprofile.tsx: 46 Attack Vector
MEDIUM Client_HTML5_Store_Sensitive_data_In_Web_Storage /public/src/pages/auth/LoginNew/PasswordCheck.tsx: 65 Attack Vector
MEDIUM Client_Privacy_Violation /public/src/pages/auth/LoginNew/LoginNew.tsx: 38 Attack Vector

Fixed Issues

Severity Issue Source File / Package
MEDIUM Client_HTML5_Store_Sensitive_data_In_Web_Storage /public/src/pages/main/Userprofile.tsx: 46
MEDIUM Client_HTML5_Store_Sensitive_data_In_Web_Storage /public/src/pages/main/Userprofile.tsx: 49
MEDIUM Client_HTML5_Store_Sensitive_data_In_Web_Storage /public/src/api/httpClient.ts: 301
MEDIUM Client_HTML5_Store_Sensitive_data_In_Web_Storage /public/src/api/httpClient.ts: 157
MEDIUM Client_HTML5_Store_Sensitive_data_In_Web_Storage /public/src/api/httpClient.ts: 49
MEDIUM Client_HTML5_Store_Sensitive_data_In_Web_Storage /public/src/api/httpClient.ts: 132
MEDIUM Client_HTML5_Store_Sensitive_data_In_Web_Storage /public/src/api/httpClient.ts: 278
MEDIUM Client_HTML5_Store_Sensitive_data_In_Web_Storage /public/src/api/httpClient.ts: 34
MEDIUM Client_HTML5_Store_Sensitive_data_In_Web_Storage /public/src/api/httpClient.ts: 89
MEDIUM Client_HTML5_Store_Sensitive_data_In_Web_Storage /public/src/pages/auth/Register/Register.tsx: 16
MEDIUM Client_HTML5_Store_Sensitive_data_In_Web_Storage /public/src/api/httpClient.ts: 141
MEDIUM Client_HTML5_Store_Sensitive_data_In_Web_Storage /public/src/api/httpClient.ts: 206
MEDIUM Client_HTML5_Store_Sensitive_data_In_Web_Storage /public/src/api/httpClient.ts: 194
MEDIUM Client_HTML5_Store_Sensitive_data_In_Web_Storage /public/src/api/httpClient.ts: 122
MEDIUM Client_HTML5_Store_Sensitive_data_In_Web_Storage /public/src/api/httpClient.ts: 222
MEDIUM Client_HTML5_Store_Sensitive_data_In_Web_Storage /public/src/api/httpClient.ts: 301
MEDIUM Client_HTML5_Store_Sensitive_data_In_Web_Storage /public/src/api/httpClient.ts: 168
MEDIUM Client_HTML5_Store_Sensitive_data_In_Web_Storage /public/src/api/httpClient.ts: 183
MEDIUM Client_HTML5_Store_Sensitive_data_In_Web_Storage /public/src/api/httpClient.ts: 299
MEDIUM Client_HTML5_Store_Sensitive_data_In_Web_Storage /public/src/api/httpClient.ts: 77
MEDIUM Client_HTML5_Store_Sensitive_data_In_Web_Storage /public/src/api/httpClient.ts: 299
MEDIUM Client_HTML5_Store_Sensitive_data_In_Web_Storage /public/src/pages/main/Userprofile.tsx: 46
MEDIUM Client_HTML5_Store_Sensitive_data_In_Web_Storage /public/src/pages/main/Userprofile.tsx: 49
MEDIUM Client_HTML5_Store_Sensitive_data_In_Web_Storage /public/src/api/httpClient.ts: 301
MEDIUM Client_HTML5_Store_Sensitive_data_In_Web_Storage /public/src/api/httpClient.ts: 141
MEDIUM Client_HTML5_Store_Sensitive_data_In_Web_Storage /public/src/api/httpClient.ts: 194
MEDIUM Client_HTML5_Store_Sensitive_data_In_Web_Storage /public/src/api/httpClient.ts: 206
MEDIUM Client_HTML5_Store_Sensitive_data_In_Web_Storage /public/src/api/httpClient.ts: 77
MEDIUM Client_HTML5_Store_Sensitive_data_In_Web_Storage /public/src/api/httpClient.ts: 299
MEDIUM Client_HTML5_Store_Sensitive_data_In_Web_Storage /public/src/api/httpClient.ts: 49
MEDIUM Client_HTML5_Store_Sensitive_data_In_Web_Storage /public/src/api/httpClient.ts: 222
MEDIUM Client_HTML5_Store_Sensitive_data_In_Web_Storage /public/src/pages/auth/Register/Register.tsx: 16
MEDIUM Client_HTML5_Store_Sensitive_data_In_Web_Storage /public/src/api/httpClient.ts: 168
MEDIUM Client_HTML5_Store_Sensitive_data_In_Web_Storage /public/src/api/httpClient.ts: 183
MEDIUM Client_HTML5_Store_Sensitive_data_In_Web_Storage /public/src/api/httpClient.ts: 89
MEDIUM Client_HTML5_Store_Sensitive_data_In_Web_Storage /public/src/api/httpClient.ts: 299
MEDIUM Client_HTML5_Store_Sensitive_data_In_Web_Storage /public/src/api/httpClient.ts: 157
MEDIUM Client_HTML5_Store_Sensitive_data_In_Web_Storage /public/src/api/httpClient.ts: 278
MEDIUM Client_HTML5_Store_Sensitive_data_In_Web_Storage /public/src/api/httpClient.ts: 132
MEDIUM Client_HTML5_Store_Sensitive_data_In_Web_Storage /public/src/api/httpClient.ts: 34
MEDIUM Client_HTML5_Store_Sensitive_data_In_Web_Storage /public/src/api/httpClient.ts: 122
MEDIUM Client_HTML5_Store_Sensitive_data_In_Web_Storage /public/src/api/httpClient.ts: 301
MEDIUM Client_HTML5_Store_Sensitive_data_In_Web_Storage /public/src/api/httpClient.ts: 301
MEDIUM Client_HTML5_Store_Sensitive_data_In_Web_Storage /public/src/api/httpClient.ts: 301
MEDIUM Client_HTML5_Store_Sensitive_data_In_Web_Storage /public/src/api/httpClient.ts: 183
MEDIUM Client_HTML5_Store_Sensitive_data_In_Web_Storage /public/src/api/httpClient.ts: 299
MEDIUM Client_HTML5_Store_Sensitive_data_In_Web_Storage /public/src/api/httpClient.ts: 299
MEDIUM Client_HTML5_Store_Sensitive_data_In_Web_Storage /public/src/pages/auth/Register/Register.tsx: 16
MEDIUM Client_HTML5_Store_Sensitive_data_In_Web_Storage /public/src/api/httpClient.ts: 77
MEDIUM Client_HTML5_Store_Sensitive_data_In_Web_Storage /public/src/api/httpClient.ts: 49
MEDIUM Client_HTML5_Store_Sensitive_data_In_Web_Storage /public/src/api/httpClient.ts: 89
MEDIUM Client_HTML5_Store_Sensitive_data_In_Web_Storage /public/src/api/httpClient.ts: 34
MEDIUM Client_HTML5_Store_Sensitive_data_In_Web_Storage /public/src/pages/main/Userprofile.tsx: 49
MEDIUM Client_HTML5_Store_Sensitive_data_In_Web_Storage /public/src/pages/main/Userprofile.tsx: 46
MEDIUM Client_HTML5_Store_Sensitive_data_In_Web_Storage /public/src/api/httpClient.ts: 157
MEDIUM Client_HTML5_Store_Sensitive_data_In_Web_Storage /public/src/api/httpClient.ts: 132
MEDIUM Client_HTML5_Store_Sensitive_data_In_Web_Storage /public/src/api/httpClient.ts: 278
MEDIUM Client_HTML5_Store_Sensitive_data_In_Web_Storage /public/src/api/httpClient.ts: 141
MEDIUM Client_HTML5_Store_Sensitive_data_In_Web_Storage /public/src/api/httpClient.ts: 222
MEDIUM Client_HTML5_Store_Sensitive_data_In_Web_Storage /public/src/api/httpClient.ts: 122
MEDIUM Client_HTML5_Store_Sensitive_data_In_Web_Storage /public/src/api/httpClient.ts: 194
MEDIUM Client_HTML5_Store_Sensitive_data_In_Web_Storage /public/src/api/httpClient.ts: 206
MEDIUM Client_HTML5_Store_Sensitive_data_In_Web_Storage /public/src/api/httpClient.ts: 168
MEDIUM Client_HTML5_Store_Sensitive_data_In_Web_Storage /public/src/api/httpClient.ts: 89
MEDIUM Client_HTML5_Store_Sensitive_data_In_Web_Storage /public/src/pages/auth/Register/Register.tsx: 16
MEDIUM Client_HTML5_Store_Sensitive_data_In_Web_Storage /public/src/api/httpClient.ts: 34
MEDIUM Client_HTML5_Store_Sensitive_data_In_Web_Storage /public/src/api/httpClient.ts: 77
MEDIUM Client_HTML5_Store_Sensitive_data_In_Web_Storage /public/src/api/httpClient.ts: 49
MEDIUM Client_HTML5_Store_Sensitive_data_In_Web_Storage /public/src/api/httpClient.ts: 49
MEDIUM Client_HTML5_Store_Sensitive_data_In_Web_Storage /public/src/api/httpClient.ts: 34
MEDIUM Client_HTML5_Store_Sensitive_data_In_Web_Storage /public/src/api/httpClient.ts: 49
MEDIUM Client_HTML5_Store_Sensitive_data_In_Web_Storage /public/src/api/httpClient.ts: 34
MEDIUM Client_Potential_XSS /public/public/vendor/js/bootstrap-datetimepicker.js: 512
MEDIUM Client_Potential_XSS /public/public/vendor/js/bootstrap-datetimepicker.js: 508
MEDIUM Client_Potential_XSS /public/public/js/bootstrap-datetimepicker.js: 512
MEDIUM Client_Potential_XSS /public/public/js/bootstrap-datetimepicker.js: 508
MEDIUM Client_Potential_XSS /public/public/vendor/progressbar/progressbar.min.js: 692
MEDIUM Client_Potential_XSS /public/public/vendor/progressbar/progressbar.js: 2144
MEDIUM Client_Potential_XSS /public/public/vendor/progressbar/progressbar.js: 2034
MEDIUM Client_Potential_XSS /public/public/vendor/progressbar/progressbar.min.js: 664
MEDIUM Client_Potential_XSS /public/public/vendor/progressbar/progressbar.min.js: 664
MEDIUM Client_Potential_XSS /public/public/vendor/fullcalendar-3.10.0/fullcalendar.js: 14518
MEDIUM Client_Potential_XSS /public/public/vendor/fullcalendar-3.10.0/fullcalendar.js: 7745
MEDIUM Client_Potential_XSS /public/public/vendor/fullcalendar-3.10.0/fullcalendar.js: 7745
MEDIUM Client_Potential_XSS /public/public/vendor/assets/vendor/venobox/venobox.js: 353
MEDIUM Client_Potential_XSS /public/public/assets/vendor/venobox/venobox.js: 353
MEDIUM Client_Potential_XSS /public/public/assets/vendor/venobox/venobox.js: 352
MEDIUM Client_Potential_XSS /public/public/vendor/assets/vendor/venobox/venobox.js: 352
MEDIUM Client_Potential_XSS /public/public/assets/vendor/venobox/venobox.js: 351
MEDIUM Client_Potential_XSS /public/public/vendor/assets/vendor/venobox/venobox.js: 351
MEDIUM Client_Potential_XSS /public/public/vendor/assets/vendor/venobox/venobox.js: 350
MEDIUM Client_Potential_XSS /public/public/assets/vendor/venobox/venobox.js: 350
MEDIUM Client_Potential_XSS /public/public/vendor/assets/vendor/venobox/venobox.js: 349
MEDIUM Client_Potential_XSS /public/public/assets/vendor/venobox/venobox.js: 349
MEDIUM Client_Potential_XSS /public/public/assets/vendor/venobox/venobox.js: 349
MEDIUM Client_Potential_XSS /public/public/vendor/assets/vendor/venobox/venobox.js: 349
MEDIUM Client_Potential_XSS /public/public/vendor/js/bootstrap-datetimepicker.js: 265
MEDIUM Client_Potential_XSS /public/public/js/bootstrap-datetimepicker.js: 265
MEDIUM Client_Potential_XSS /public/public/vendor/js/bootstrap-datetimepicker.js: 250
MEDIUM Client_Potential_XSS /public/public/js/bootstrap-datetimepicker.js: 250
MEDIUM Client_Potential_XSS /public/public/assets/vendor/owl.carousel/owl.carousel.js: 612
MEDIUM Client_Potential_XSS /public/public/vendor/assets/vendor/owl.carousel/owl.carousel.js: 612
MEDIUM Client_Potential_XSS /public/public/vendor/js/bootstrap-datetimepicker.js: 274
MEDIUM Client_Potential_XSS /public/public/js/bootstrap-datetimepicker.js: 274
MEDIUM Client_Potential_XSS /public/public/js/bootstrap-datetimepicker.js: 269
MEDIUM Client_Potential_XSS /public/public/vendor/js/bootstrap-datetimepicker.js: 269
MEDIUM Client_Potential_XSS /public/public/js/bootstrap-datetimepicker.js: 259
MEDIUM Client_Potential_XSS /public/public/vendor/js/bootstrap-datetimepicker.js: 259
MEDIUM Client_Potential_XSS /public/public/vendor/js/bootstrap-datetimepicker.js: 254
MEDIUM Client_Potential_XSS /public/public/js/bootstrap-datetimepicker.js: 254
MEDIUM Client_Potential_XSS /public/public/js/bootstrap-datetimepicker.js: 245
MEDIUM Client_Potential_XSS /public/public/vendor/js/bootstrap-datetimepicker.js: 245
MEDIUM Client_Potential_XSS /public/public/js/bootstrap-datetimepicker.js: 241
MEDIUM Client_Potential_XSS /public/public/vendor/js/bootstrap-datetimepicker.js: 241
MEDIUM Client_Potential_XSS /public/public/assets/js/main.js: 63
MEDIUM Client_Potential_XSS /public/public/vendor/assets/js/main.js: 62
MEDIUM Client_Potential_XSS /public/public/vendor/assets/vendor/venobox/venobox.js: 739
MEDIUM Client_Potential_XSS /public/public/assets/vendor/venobox/venobox.js: 739
MEDIUM Client_Potential_XSS /public/public/vendor/js/bootstrap-datetimepicker.js: 324
MEDIUM Client_Potential_XSS /public/public/js/bootstrap-datetimepicker.js: 324
MEDIUM Client_Potential_XSS /public/public/js/bootstrap-datetimepicker.js: 321
MEDIUM Client_Potential_XSS /public/public/vendor/js/bootstrap-datetimepicker.js: 321
MEDIUM Client_Potential_XSS /public/public/vendor/js/bootstrap-datetimepicker.js: 318
MEDIUM Client_Potential_XSS /public/public/js/bootstrap-datetimepicker.js: 318
MEDIUM Client_Potential_XSS /public/public/js/bootstrap-datetimepicker.js: 315
MEDIUM Client_Potential_XSS /public/public/vendor/js/bootstrap-datetimepicker.js: 315
MEDIUM Client_Potential_XSS /public/public/js/bootstrap-datetimepicker.js: 281
MEDIUM Client_Potential_XSS /public/public/js/bootstrap-datetimepicker.js: 281
MEDIUM Client_Potential_XSS /public/public/vendor/js/bootstrap-datetimepicker.js: 281
MEDIUM Client_Potential_XSS /public/public/vendor/js/bootstrap-datetimepicker.js: 281
MEDIUM Client_Potential_XSS

More results are available on AST platform

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants