[
https://issues.apache.org/jira/browse/HBASE-30379?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Work on HBASE-30379 started by Dávid Paksy.
-------------------------------------------
> Update vulnerable website dependencies
> --------------------------------------
>
> Key: HBASE-30379
> URL: https://issues.apache.org/jira/browse/HBASE-30379
> Project: HBase
> Issue Type: Task
> Components: dependabot, dependencies, security
> Reporter: Dávid Paksy
> Assignee: Dávid Paksy
> Priority: Major
>
> {noformat}
> # npm audit report
> @vitest/mocker 2.1.0 - 4.1.10
> Severity: moderate
> Vitest: Path Traversal / Arbitrary File Read via @vitest/mocker Redirect Mock
> - https://github.com/advisories/GHSA-82fw-gwwq-j7x9
> fix available via `npm audit fix`
> node_modules/@vitest/mocker
> vitest 2.1.0-beta.1 - 4.1.10
> Depends on vulnerable versions of @vitest/mocker
> node_modules/vitest
> js-yaml 4.0.0 - 4.3.1
> Severity: high
> js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources -
> https://github.com/advisories/GHSA-2883-xcg3-v3hh
> fix available via `npm audit fix`
> node_modules/js-yaml
> morgan <1.12.0
> Severity: moderate
> morgan vulnerable to Log Forging via unescaped Unicode line separators -
> https://github.com/advisories/GHSA-jxfw-x594-9x9m
> fix available via `npm audit fix`
> node_modules/morgan
> 4 vulnerabilities (3 moderate, 1 high)
> {noformat}
--
This message was sent by Atlassian Jira
(v8.20.10#820010)