[ 
https://issues.apache.org/jira/browse/HBASE-30442?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Dávid Paksy reassigned HBASE-30442:
-----------------------------------

    Assignee: Dávid Paksy

> Upgrade brace-expansion and fast-uri in website to fix known security 
> vulnerabilities
> -------------------------------------------------------------------------------------
>
>                 Key: HBASE-30442
>                 URL: https://issues.apache.org/jira/browse/HBASE-30442
>             Project: HBase
>          Issue Type: Task
>          Components: dependencies, security, website
>            Reporter: Dávid Paksy
>            Assignee: Dávid Paksy
>            Priority: Major
>
> npm audit report before:
>  
> {noformat}
> # npm audit report
> brace-expansion  <=1.1.20 || 4.0.0 - 5.0.11
> Severity: high
> brace-expansion: Quadratic-time expansion of the `{a},b}` rewrite causes CPU 
> denial of service - https://github.com/advisories/GHSA-q2hr-2g5m-vwhr
> brace-expansion: Quadratic-time expansion of the `{a},b}` rewrite causes CPU 
> denial of service - https://github.com/advisories/GHSA-q2hr-2g5m-vwhr
> brace-expansion: DoS via uncontrolled recursion on nested brace groups 
> causing stack exhaustion - https://github.com/advisories/GHSA-qhr7-859c-m2p7
> brace-expansion: DoS via uncontrolled recursion on nested brace groups 
> causing stack exhaustion - https://github.com/advisories/GHSA-qhr7-859c-m2p7
> brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing 
> stack exhaustion - https://github.com/advisories/GHSA-6j4f-fj2g-mc7p
> brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing 
> stack exhaustion - https://github.com/advisories/GHSA-6j4f-fj2g-mc7p
> fix available via `npm audit fix`
> node_modules/brace-expansion
> node_modules/serve-handler/node_modules/brace-expansion
> fast-uri  3.0.0 - 3.1.7
> Severity: moderate
> fast-uri vulnerable to inconsistent host case normalization via 
> percent-encoded octets - https://github.com/advisories/GHSA-hrr3-gc8f-f4qj
> fix available via `npm audit fix`
> node_modules/fast-uri
> 2 vulnerabilities (1 moderate, 1 high)
> To address all issues, run:
>   npm audit fix
> {noformat}



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to