Code Monkey home page Code Monkey logo

hima's People


himavanth avatar


 avatar  avatar

hima's Issues

audit report

"title": "Denial of Service",
"module": "node-fetch",
"Description": "Node Fetch did not honor the size option after following a redirect, which means that when a content size was over the limit, a FetchError would never get thrown and the process would end without failure.\n\nFor most people, this fix will have a little or no impact. However, if you are relying on node-fetch to gate files above a size, the impact could be significant, for example: If you don't double-check the size of the data after fetch() has completed, your JS thread could get tied up doing work on a large file (DoS) and/or cost you money in computing."
"title": "Server-Side Request Forgery",
"module": "axios",
"Description": "The axios NPM package before 0.21.1 contains a Server-Side Request Forgery (SSRF) vulnerability where an attacker is able to bypass a proxy by providing a URL that responds with a redirect to a restricted host or IP address."

npm audit found vulnerabilities

=== npm audit security report ===                        
│                                Manual Review                                 │
│            Some vulnerabilities require your attention to resolve            │
│                                                                              │
│         Visit for additional guidance          │
│ High          │ Server-Side Request Forgery                                  │
│ Package       │ axios                                                        │
│ Patched in    │ >=0.21.1                                                     │
│ Dependency of │ cloudevents-sdk                                              │
│ Path          │ cloudevents-sdk > axios                                      │
│ More info     │                            │
found 1 high severity vulnerability in 14 scanned packages
  1 vulnerability requires manual review. See the full report for details.

High and/or Critical vulnerability found in npm audit of FF App

Server-Side Request Forgery in module axios

The `axios` NPM package before 0.21.1 contains a Server-Side Request Forgery (SSRF) vulnerability where an attacker is able to bypass a proxy by providing a URL that responds with a redirect to a restricted host or IP address.


=== npm audit security report ===

Run npm update axios --depth 1 to resolve 1 vulnerability

│ High │ Server-Side Request Forgery │
│ Package │ axios │
│ Dependency of │ axios │
│ Path │ axios │
│ More info │

found 1 high severity vulnerability in 2 scanned packages
run npm audit fix to fix 1 of them.

npm audit found vulnerabilities

=== npm audit security report ===                        
│                                Manual Review                                 │
│            Some vulnerabilities require your attention to resolve            │
│                                                                              │
│         Visit for additional guidance          │
│ Low           │ Denial of Service                                            │
│ Package       │ node-fetch                                                   │
│ Patched in    │ >=2.6.1 <3.0.0-beta.1|| >= 3.0.0-beta.9                      │
│ Dependency of │ @adobe/aio-sdk                                               │
│ Path          │ @adobe/aio-sdk > @adobe/aio-lib-audience-manager-cd >        │
│               │ swagger-client > cross-fetch > node-fetch                    │
│ More info     │                            │
│ Low           │ Denial of Service                                            │
│ Package       │ node-fetch                                                   │
│ Patched in    │ >=2.6.1 <3.0.0-beta.1|| >= 3.0.0-beta.9                      │
│ Dependency of │ @adobe/aio-sdk                                               │
│ Path          │ @adobe/aio-sdk > @adobe/aio-lib-campaign-standard >          │
│               │ swagger-client > cross-fetch > node-fetch                    │
│ More info     │                            │
│ Low           │ Denial of Service                                            │
│ Package       │ node-fetch                                                   │
│ Patched in    │ >=2.6.1 <3.0.0-beta.1|| >= 3.0.0-beta.9                      │
│ Dependency of │ @adobe/aio-sdk                                               │
│ Path          │ @adobe/aio-sdk > @adobe/aio-lib-customer-profile >           │
│               │ swagger-client > cross-fetch > node-fetch                    │
│ More info     │                            │
│ Low           │ Denial of Service                                            │
│ Package       │ node-fetch                                                   │
│ Patched in    │ >=2.6.1 <3.0.0-beta.1|| >= 3.0.0-beta.9                      │
│ Dependency of │ @openwhisk/wskdebug [dev]                                    │
│ Path          │ @openwhisk/wskdebug > isomorphic-fetch > node-fetch          │
│ More info     │                            │
│ High          │ Server-Side Request Forgery                                  │
│ Package       │ axios                                                        │
│ Patched in    │ >=0.21.1                                                     │
│ Dependency of │ cloudevents-sdk                                              │
│ Path          │ cloudevents-sdk > axios                                      │
│ More info     │                            │
found 5 vulnerabilities (4 low, 1 high) in 1097 scanned packages
  5 vulnerabilities require manual review. See the full report for details.


"actions": [
"action": "update",
"resolves": [
"id": 1594,
"path": "axios",
"dev": false,
"optional": false,
"bundled": false
"module": "axios",
"target": "0.21.1",
"depth": 1
"advisories": {
"1594": {
"findings": [
"version": "0.21.0",
"paths": [
"id": 1594,
"created": "2021-01-04T21:04:59.346Z",
"updated": "2021-01-04T21:05:54.214Z",
"deleted": null,
"title": "Server-Side Request Forgery",
"found_by": {
"link": "",
"name": "Anonymous",
"email": ""
"reported_by": {
"link": "",
"name": "Anonymous",
"email": ""
"module_name": "axios",
"cves": [
"vulnerable_versions": "<0.21.1",
"patched_versions": ">=0.21.1",
"overview": "The axios NPM package before 0.21.1 contains a Server-Side Request Forgery (SSRF) vulnerability where an attacker is able to bypass a proxy by providing a URL that responds with a redirect to a restricted host or IP address.",
"recommendation": "Upgrade to 0.21.1 or later.",
"references": "- Github Issue\n- Fix commit\n- GitHub Advisory\n- Snyk Report",
"access": "public",
"severity": "high",
"cwe": "CWE-918",
"metadata": {
"module_type": "",
"exploitability": 5,
"affected_components": ""
"url": ""
"muted": [],
"metadata": {
"vulnerabilities": {
"info": 0,
"low": 0,
"moderate": 0,
"high": 1,
"critical": 0
"dependencies": 2,
"devDependencies": 0,
"optionalDependencies": 0,
"totalDependencies": 2
"runId": "4903792b-b6f8-436e-aae2-a85793612e63"

High and/or Critical vulnerability found in npm audit of FF App

Server-Side Request Forgery in module axios

The `axios` NPM package before 0.21.1 contains a Server-Side Request Forgery (SSRF) vulnerability where an attacker is able to bypass a proxy by providing a URL that responds with a redirect to a restricted host or IP address.

High and/or Critical vulnerability found in npm audit

=== npm audit security report ===                        
│                                Manual Review                                 │
│            Some vulnerabilities require your attention to resolve            │
│                                                                              │
│         Visit for additional guidance          │
│ Low           │ Denial of Service                                            │
│ Package       │ node-fetch                                                   │
│ Patched in    │ >=2.6.1 <3.0.0-beta.1|| >= 3.0.0-beta.9                      │
│ Dependency of │ @adobe/aio-sdk                                               │
│ Path          │ @adobe/aio-sdk > @adobe/aio-lib-audience-manager-cd >        │
│               │ swagger-client > cross-fetch > node-fetch                    │
│ More info     │                            │
│ Low           │ Denial of Service                                            │
│ Package       │ node-fetch                                                   │
│ Patched in    │ >=2.6.1 <3.0.0-beta.1|| >= 3.0.0-beta.9                      │
│ Dependency of │ @adobe/aio-sdk                                               │
│ Path          │ @adobe/aio-sdk > @adobe/aio-lib-campaign-standard >          │
│               │ swagger-client > cross-fetch > node-fetch                    │
│ More info     │                            │
│ Low           │ Denial of Service                                            │
│ Package       │ node-fetch                                                   │
│ Patched in    │ >=2.6.1 <3.0.0-beta.1|| >= 3.0.0-beta.9                      │
│ Dependency of │ @adobe/aio-sdk                                               │
│ Path          │ @adobe/aio-sdk > @adobe/aio-lib-customer-profile >           │
│               │ swagger-client > cross-fetch > node-fetch                    │
│ More info     │                            │
│ Low           │ Denial of Service                                            │
│ Package       │ node-fetch                                                   │
│ Patched in    │ >=2.6.1 <3.0.0-beta.1|| >= 3.0.0-beta.9                      │
│ Dependency of │ @openwhisk/wskdebug [dev]                                    │
│ Path          │ @openwhisk/wskdebug > isomorphic-fetch > node-fetch          │
│ More info     │                            │
│ High          │ Server-Side Request Forgery                                  │
│ Package       │ axios                                                        │
│ Patched in    │ >=0.21.1                                                     │
│ Dependency of │ cloudevents-sdk                                              │
│ Path          │ cloudevents-sdk > axios                                      │
│ More info     │                            │
found 5 vulnerabilities (4 low, 1 high) in 1097 scanned packages
  5 vulnerabilities require manual review. See the full report for details.

audit report

Server-Side Request Forgery in module axios

The `axios` NPM package before 0.21.1 contains a Server-Side Request Forgery (SSRF) vulnerability where an attacker is able to bypass a proxy by providing a URL that responds with a redirect to a restricted host or IP address.

audit report

"title": "Denial of Service",
"module": "node-fetch",
"Description": "Node Fetch did not honor the size option after following a redirect, which means that when a content size was over the limit, a FetchError would never get thrown and the process would end without failure.\n\nFor most people, this fix will have a little or no impact. However, if you are relying on node-fetch to gate files above a size, the impact could be significant, for example: If you don't double-check the size of the data after fetch() has completed, your JS thread could get tied up doing work on a large file (DoS) and/or cost you money in computing."
"title": "Server-Side Request Forgery",
"module": "axios",
"Description": "The axios NPM package before 0.21.1 contains a Server-Side Request Forgery (SSRF) vulnerability where an attacker is able to bypass a proxy by providing a URL that responds with a redirect to a restricted host or IP address."

from curl

[{ 'title': 'Denial of Service', }]


=== npm audit security report ===

Run npm update axios --depth 1 to resolve 1 vulnerability

│ High │ Server-Side Request Forgery │
│ Package │ axios │
│ Dependency of │ axios │
│ Path │ axios │
│ More info │

found 1 high severity vulnerability in 2 scanned packages
run npm audit fix to fix 1 of them.

npm audit found vulnerabilities

=== npm audit security report ===                        
│                                Manual Review                                 │
│            Some vulnerabilities require your attention to resolve            │
│                                                                              │
│         Visit for additional guidance          │
│ Low           │ Denial of Service                                            │
│ Package       │ node-fetch                                                   │
│ Patched in    │ >=2.6.1 <3.0.0-beta.1|| >= 3.0.0-beta.9                      │
│ Dependency of │ @adobe/aio-sdk                                               │
│ Path          │ @adobe/aio-sdk > @adobe/aio-lib-audience-manager-cd >        │
│               │ swagger-client > cross-fetch > node-fetch                    │
│ More info     │                            │
│ Low           │ Denial of Service                                            │
│ Package       │ node-fetch                                                   │
│ Patched in    │ >=2.6.1 <3.0.0-beta.1|| >= 3.0.0-beta.9                      │
│ Dependency of │ @adobe/aio-sdk                                               │
│ Path          │ @adobe/aio-sdk > @adobe/aio-lib-campaign-standard >          │
│               │ swagger-client > cross-fetch > node-fetch                    │
│ More info     │                            │
│ Low           │ Denial of Service                                            │
│ Package       │ node-fetch                                                   │
│ Patched in    │ >=2.6.1 <3.0.0-beta.1|| >= 3.0.0-beta.9                      │
│ Dependency of │ @adobe/aio-sdk                                               │
│ Path          │ @adobe/aio-sdk > @adobe/aio-lib-customer-profile >           │
│               │ swagger-client > cross-fetch > node-fetch                    │
│ More info     │                            │
│ Low           │ Denial of Service                                            │
│ Package       │ node-fetch                                                   │
│ Patched in    │ >=2.6.1 <3.0.0-beta.1|| >= 3.0.0-beta.9                      │
│ Dependency of │ @openwhisk/wskdebug [dev]                                    │
│ Path          │ @openwhisk/wskdebug > isomorphic-fetch > node-fetch          │
│ More info     │                            │
│ High          │ Server-Side Request Forgery                                  │
│ Package       │ axios                                                        │
│ Patched in    │ >=0.21.1                                                     │
│ Dependency of │ cloudevents-sdk                                              │
│ Path          │ cloudevents-sdk > axios                                      │
│ More info     │                            │
found 5 vulnerabilities (4 low, 1 high) in 1097 scanned packages
  5 vulnerabilities require manual review. See the full report for details.

npm audit found vulnerabilities

=== npm audit security report ===                        
│                                Manual Review                                 │
│            Some vulnerabilities require your attention to resolve            │
│                                                                              │
│         Visit for additional guidance          │
│ Low           │ Denial of Service                                            │
│ Package       │ node-fetch                                                   │
│ Patched in    │ >=2.6.1 <3.0.0-beta.1|| >= 3.0.0-beta.9                      │
│ Dependency of │ @adobe/aio-sdk                                               │
│ Path          │ @adobe/aio-sdk > @adobe/aio-lib-audience-manager-cd >        │
│               │ swagger-client > cross-fetch > node-fetch                    │
│ More info     │                            │
│ Low           │ Denial of Service                                            │
│ Package       │ node-fetch                                                   │
│ Patched in    │ >=2.6.1 <3.0.0-beta.1|| >= 3.0.0-beta.9                      │
│ Dependency of │ @adobe/aio-sdk                                               │
│ Path          │ @adobe/aio-sdk > @adobe/aio-lib-campaign-standard >          │
│               │ swagger-client > cross-fetch > node-fetch                    │
│ More info     │                            │
│ Low           │ Denial of Service                                            │
│ Package       │ node-fetch                                                   │
│ Patched in    │ >=2.6.1 <3.0.0-beta.1|| >= 3.0.0-beta.9                      │
│ Dependency of │ @adobe/aio-sdk                                               │
│ Path          │ @adobe/aio-sdk > @adobe/aio-lib-customer-profile >           │
│               │ swagger-client > cross-fetch > node-fetch                    │
│ More info     │                            │
│ Low           │ Denial of Service                                            │
│ Package       │ node-fetch                                                   │
│ Patched in    │ >=2.6.1 <3.0.0-beta.1|| >= 3.0.0-beta.9                      │
│ Dependency of │ @openwhisk/wskdebug [dev]                                    │
│ Path          │ @openwhisk/wskdebug > isomorphic-fetch > node-fetch          │
│ More info     │                            │
│ High          │ Server-Side Request Forgery                                  │
│ Package       │ axios                                                        │
│ Patched in    │ >=0.21.1                                                     │
│ Dependency of │ cloudevents-sdk                                              │
│ Path          │ cloudevents-sdk > axios                                      │
│ More info     │                            │
found 5 vulnerabilities (4 low, 1 high) in 1097 scanned packages
  5 vulnerabilities require manual review. See the full report for details.

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.