Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

npm vulnerabilities #15

Open
y1n opened this issue Jul 13, 2019 · 0 comments
Open

npm vulnerabilities #15

y1n opened this issue Jul 13, 2019 · 0 comments

Comments

@y1n
Copy link

y1n commented Jul 13, 2019

Hello! Could you please update packages to eliminate following vulnerabilities? :)

 Low             Regular Expression Denial of Service

  Package         debug

  Patched in      >= 2.6.9 < 3.0.0 || >= 3.1.0

  Dependency of   bitcoin-receive-payments

  Path            bitcoin-receive-payments > bitcoin-live-transactions >
                  socket.io-client > debug

  More info       https://nodesecurity.io/advisories/534


  Low             Regular Expression Denial of Service

  Package         debug

  Patched in      >= 2.6.9 < 3.0.0 || >= 3.1.0

  Dependency of   bitcoin-receive-payments

  Path            bitcoin-receive-payments > bitcoin-live-transactions >
                  socket.io-client > engine.io-client > debug

  More info       https://nodesecurity.io/advisories/534


  Low             Regular Expression Denial of Service

  Package         debug

  Patched in      >= 2.6.9 < 3.0.0 || >= 3.1.0

  Dependency of   bitcoin-receive-payments

  Path            bitcoin-receive-payments > socket.io > debug

  More info       https://nodesecurity.io/advisories/534


  Low             Regular Expression Denial of Service

  Package         debug

  Patched in      >= 2.6.9 < 3.0.0 || >= 3.1.0

  Dependency of   bitcoin-receive-payments

  Path            bitcoin-receive-payments > socket.io > engine.io > debug

  More info       https://nodesecurity.io/advisories/534


  Low             Regular Expression Denial of Service

  Package         debug

  Patched in      >= 2.6.9 < 3.0.0 || >= 3.1.0

  Dependency of   bitcoin-receive-payments

  Path            bitcoin-receive-payments > socket.io > socket.io-adapter >
                  debug

  More info       https://nodesecurity.io/advisories/534


  Low             Regular Expression Denial of Service

  Package         debug

  Patched in      >= 2.6.9 < 3.0.0 || >= 3.1.0

  Dependency of   bitcoin-receive-payments

  Path            bitcoin-receive-payments > socket.io > socket.io-client >
                  debug

  More info       https://nodesecurity.io/advisories/534


  Low             Regular Expression Denial of Service

  Package         debug

  Patched in      >= 2.6.9 < 3.0.0 || >= 3.1.0

  Dependency of   bitcoin-receive-payments

  Path            bitcoin-receive-payments > socket.io > socket.io-client >
                  engine.io-client > debug

  More info       https://nodesecurity.io/advisories/534


  Low             Regular Expression Denial of Service

  Package         debug

  Patched in      >= 2.6.9 < 3.0.0 || >= 3.1.0

  Dependency of   bitcoin-receive-payments

  Path            bitcoin-receive-payments > socket.io-client > debug

  More info       https://nodesecurity.io/advisories/534


  Low             Regular Expression Denial of Service

  Package         debug

  Patched in      >= 2.6.9 < 3.0.0 || >= 3.1.0

  Dependency of   bitcoin-receive-payments

  Path            bitcoin-receive-payments > socket.io-client >
                  engine.io-client > debug

  More info       https://nodesecurity.io/advisories/534


  Low             Regular Expression Denial of Service

  Package         debug

  Patched in      >= 2.6.9 < 3.0.0 || >= 3.1.0

  Dependency of   bitcoin-receive-payments

  Path            bitcoin-receive-payments > bitcoin-live-transactions >
                  socket.io-client > socket.io-parser > debug

  More info       https://nodesecurity.io/advisories/534


  Low             Regular Expression Denial of Service

  Package         debug

  Patched in      >= 2.6.9 < 3.0.0 || >= 3.1.0

  Dependency of   bitcoin-receive-payments

  Path            bitcoin-receive-payments > socket.io > socket.io-adapter >
                  socket.io-parser > debug

  More info       https://nodesecurity.io/advisories/534


  Low             Regular Expression Denial of Service

  Package         debug

  Patched in      >= 2.6.9 < 3.0.0 || >= 3.1.0

  Dependency of   bitcoin-receive-payments

  Path            bitcoin-receive-payments > socket.io > socket.io-client >
                  socket.io-parser > debug

  More info       https://nodesecurity.io/advisories/534


  Low             Regular Expression Denial of Service

  Package         debug

  Patched in      >= 2.6.9 < 3.0.0 || >= 3.1.0

  Dependency of   bitcoin-receive-payments

  Path            bitcoin-receive-payments > socket.io > socket.io-parser >
                  debug

  More info       https://nodesecurity.io/advisories/534


  Low             Regular Expression Denial of Service

  Package         debug

  Patched in      >= 2.6.9 < 3.0.0 || >= 3.1.0

  Dependency of   bitcoin-receive-payments

  Path            bitcoin-receive-payments > socket.io-client >
                  socket.io-parser > debug

  More info       https://nodesecurity.io/advisories/534


  High            Regular Expression Denial of Service

  Package         parsejson

  Patched in      No patch available

  Dependency of   bitcoin-receive-payments

  Path            bitcoin-receive-payments > bitcoin-live-transactions >
                  socket.io-client > engine.io-client > parsejson

  More info       https://nodesecurity.io/advisories/528


  High            Regular Expression Denial of Service

  Package         parsejson

  Patched in      No patch available

  Dependency of   bitcoin-receive-payments

  Path            bitcoin-receive-payments > socket.io > socket.io-client >
                  engine.io-client > parsejson

  More info       https://nodesecurity.io/advisories/528


  High            Regular Expression Denial of Service

  Package         parsejson

  Patched in      No patch available

  Dependency of   bitcoin-receive-payments

  Path            bitcoin-receive-payments > socket.io-client >
                  engine.io-client > parsejson

  More info       https://nodesecurity.io/advisories/528


  High            Prototype Pollution

  Package         lodash

  Patched in      >=4.17.11

  Dependency of   bitcoin-receive-payments

  Path            bitcoin-receive-payments > bitcore-lib > lodash

  More info       https://nodesecurity.io/advisories/782


  Low             Prototype Pollution

  Package         lodash

  Patched in      >=4.17.5

  Dependency of   bitcoin-receive-payments

  Path            bitcoin-receive-payments > bitcore-lib > lodash

  More info       https://nodesecurity.io/advisories/577
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant