[Snyk] Fix for 11 vulnerabilities
This PR was automatically created by Snyk using the credentials of a real user.
Snyk has created this PR to fix one or more vulnerable packages in the `npm` dependencies of this project.
Changes included in this PR
-
Changes to the following files to upgrade the vulnerable dependencies to a fixed version:
- package.json
- package-lock.json
-
Adding or updating a Snyk policy (.snyk) file; this file is required in order to apply Snyk vulnerability patches. Find out more.
Vulnerabilities that will be fixed
With an upgrade:
| Severity | Priority Score (*) | Issue | Breaking Change | Exploit Maturity |
|---|---|---|---|---|
| 619/1000 Why? Has a fix available, CVSS 8.1 |
Prototype Pollution SNYK-JS-AJV-584908 |
No | No Known Exploit | |
| 589/1000 Why? Has a fix available, CVSS 7.5 |
Directory Traversal SNYK-JS-MOMENT-2440688 |
No | No Known Exploit | |
| 696/1000 Why? Proof of Concept exploit, Has a fix available, CVSS 7.5 |
Regular Expression Denial of Service (ReDoS) SNYK-JS-MOMENT-2944238 |
No | Proof of Concept | |
| 601/1000 Why? Proof of Concept exploit, Has a fix available, CVSS 5.6 |
Prototype Pollution SNYK-JS-MONGOOSE-1086688 |
No | Proof of Concept | |
| 671/1000 Why? Proof of Concept exploit, Has a fix available, CVSS 7 |
Prototype Pollution SNYK-JS-MONGOOSE-2961688 |
No | Proof of Concept | |
| 601/1000 Why? Proof of Concept exploit, Has a fix available, CVSS 5.6 |
Prototype Pollution SNYK-JS-MPATH-1577289 |
No | Proof of Concept | |
| 686/1000 Why? Proof of Concept exploit, Has a fix available, CVSS 7.3 |
Prototype Pollution SNYK-JS-MQUERY-1050858 |
No | Proof of Concept | |
| 696/1000 Why? Proof of Concept exploit, Has a fix available, CVSS 7.5 |
Prototype Pollution SNYK-JS-MQUERY-1089718 |
No | Proof of Concept | |
| 479/1000 Why? Has a fix available, CVSS 5.3 |
Regular Expression Denial of Service (ReDoS) SNYK-JS-REDIS-1255645 |
Yes | No Known Exploit | |
| 399/1000 Why? Has a fix available, CVSS 3.7 |
Cross-site Scripting (XSS) SNYK-JS-STRIPTAGS-1312310 |
No | No Known Exploit |
(*) Note that the real score may have changed since the PR was raised.
Commit messages
Package name: ajv
The new version differs by 233 commits.- 521c3a5 6.12.3
- bd7107b Merge pull request #1229 from ajv-validator/dependabot/npm_and_yarn/mocha-8.0.1
- 9c26bb2 Merge pull request #1234 from ajv-validator/dependabot/npm_and_yarn/eslint-7.3.1
- c6a6daa Merge branch 'master' into dependabot/npm_and_yarn/mocha-8.0.1
- 15eda23 Merge branch 'master' into dependabot/npm_and_yarn/eslint-7.3.1
- d6aabb8 test: remove node 8 from travis test
- c4801ca Merge pull request #1242 from ajv-validator/refactor
- 988982d ignore proto properties
- f2b1e3d whitespace
- 65e3678 Merge pull request #1239 from GrahamLea/patch-1
- 68d72c4 update regex
- 9c009a9 validate numbers in multipleOf
- 332b30d Merge pull request #1241 from ajv-validator/refactor
- 1105fd5 ignore proto properties
- 65b2f7d validate numbers in schemas during schema compilation
- 24d4f8f remove code post-processing
- fd64fb4 Add link to CSP section in Security section
- 0e2c346 Add Contents link to CSP section
- c581ff3 Clarify limitations of ajv-pack in README
- 0006f34 Document pre-compiled schemas for CSP in README
- 140cfa6 Merge pull request #1238 from cvlab/patch-1
- e7f0c81 Fix mistype in README.md
- 54c96b0 Bump eslint from 6.8.0 to 7.3.1
- 854dbef Bump mocha from 7.2.0 to 8.0.1
Package name: mongoose
The new version differs by 250 commits.- ca7996b chore: release 5.13.15
- e75732a Merge pull request #12307 from Automattic/vkarpov15/fix-5x-build
- a1144dc test: run node 7 tests with upgraded npm re: #12297
- dfc4ad7 test: try upgrading npm for node v4 tests re: #12297
- b9e985c test: more strict @ types/node version
- 4d813fa test: fix @ types/node version in tests re: #12297
- 99b4189 Merge pull request #12297 from shubanker/issue/prototype-pollution-5.x-patch
- 5eb11dd made function non async
- 6a19731 fix(schema): disallow setting __proto__ when creating schema with dotted properties
- a2ec28d Merge pull request #11366 from laissonsilveira/5.x
- 05ce577 Fix broken link from findandmodify method deprecation
- d2b846f chore: release 5.13.14
- 69c1f6c docs(models): fix up nModified example for 5.x
- 4cfc4d6 fix(timestamps): avoid setting `createdAt` on documents that already exist but dont have createdAt
- a738440 chore: release 5.13.13
- 4d12a62 Merge pull request #10942 from jneal-afs/fix-query-set-ts-type
- c3463c4 Merge pull request #10916 from iovanom/gh-10902-v5
- ff5ddb5 fix: hardcode base 10 for nodeMajorVersion parseInt() call
- d205c4d make value optional
- c6fd7f7 Fix ts types for query set
- 22e9b3b [gh-10902 v5] Add node major version to utils
- 5468642 [gh-10902 v5] Emit end event in before close
- 271bc60 Merge pull request #10910 from lorand-horvath/patch-2
- b7ebeec Update mongodb driver to 3.7.3
Package name: redis
The new version differs by 142 commits.- fc28860 Bump version to 3.1.1 (#1597)
- 2d11b6d fix #1569 - improve monitor_regex (#1595)
- 7e77de8 Add Chat (#1594)
- 5d3e995 Merge branch 'master' of https://github.com/NodeRedis/node-redis
- b797cf2 add user to README.md
- 79f34c2 Bump version to 3.1.0 (#1590)
- 7fdc54e fix for 428e1c8a7b2322c2650294638cb1663ac5692728 - fix auth retry when redis is in loading state
- 09f0fe8 "fix" tests
- 428e1c8 Add support for Redis 6 `auth pass [user]` (#1508)
- bb208d0 Add codeclimate badge (#1572)
- 47e2e38 Exclude examples from deepsource (#1579)
- fbca5cd Upgrade node and dependencies (#1578)
- 2188744 Create codeql-analysis.yml (#1577)
- 32861b5 Create .deepsource.toml (#1574)
- 2a34d41 Add LGTM badge (#1571)
- 69b7094 Workflows fixes (#1570)
- 49c4131 Merge pull request #1531 from marnikvde/improve-docs
- 3c8ff5c Merge branch 'master' into improve-docs
- 685a72d Merge pull request #1277 from dcharbonnier/patch-1
- 055f5c5 Merge branch 'master' into patch-1
- c78b6d5 Merge pull request #1527 from heynikhil/patch-1
- 53f1468 Merge branch 'master' into patch-1
- 232f191 Merge pull request #1563 from lebseu/patch-1
- e4cb073 Update README.md
With a Snyk patch:
| Severity | Priority Score (*) | Issue | Exploit Maturity |
|---|---|---|---|
| 731/1000 Why? Proof of Concept exploit, Has a fix available, CVSS 8.2 |
Prototype Pollution SNYK-JS-LODASH-567746 |
Proof of Concept |
(*) Note that the real score may have changed since the PR was raised.
Check the changes in this PR to ensure they won't cause issues with your project.
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📚 Read more about Snyk's upgrade and patch logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Cross-site Scripting (XSS) 🦉 Regular Expression Denial of Service (ReDoS) 🦉 Prototype Pollution 🦉 More lessons are available in Snyk Learn