[ 
https://issues.apache.org/jira/browse/HBASE-30379?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Work on HBASE-30379 started by Dávid Paksy.
-------------------------------------------
> Update vulnerable website dependencies
> --------------------------------------
>
>                 Key: HBASE-30379
>                 URL: https://issues.apache.org/jira/browse/HBASE-30379
>             Project: HBase
>          Issue Type: Task
>          Components: dependabot, dependencies, security
>            Reporter: Dávid Paksy
>            Assignee: Dávid Paksy
>            Priority: Major
>
> {noformat}
> # npm audit report
> @vitest/mocker  2.1.0 - 4.1.10
> Severity: moderate
> Vitest: Path Traversal / Arbitrary File Read via @vitest/mocker Redirect Mock 
> - https://github.com/advisories/GHSA-82fw-gwwq-j7x9
> fix available via `npm audit fix`
> node_modules/@vitest/mocker
>   vitest  2.1.0-beta.1 - 4.1.10
>   Depends on vulnerable versions of @vitest/mocker
>   node_modules/vitest
> js-yaml  4.0.0 - 4.3.1
> Severity: high
> js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources - 
> https://github.com/advisories/GHSA-2883-xcg3-v3hh
> fix available via `npm audit fix`
> node_modules/js-yaml
> morgan  <1.12.0
> Severity: moderate
> morgan vulnerable to Log Forging via unescaped Unicode line separators - 
> https://github.com/advisories/GHSA-jxfw-x594-9x9m
> fix available via `npm audit fix`
> node_modules/morgan
> 4 vulnerabilities (3 moderate, 1 high)
> {noformat}



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to