msvzero / buscador_de_recetas Goto Github PK
View Code? Open in Web Editor NEWBuscador de recetas, utilizando Reactjs y Redux.
Buscador de recetas, utilizando Reactjs y Redux.
A library for finding and using SSH public keys
path: /Buscador_de_Recetas/node_modules/.staging/sshpk-c14b0a1f/package.json
Library home page: https://registry.npmjs.org/sshpk/-/sshpk-1.13.0.tgz
Dependency Hierarchy:
Versions of sshpk before 1.14.1 are vulnerable to regular expression denial of service when parsing crafted invalid public keys.
Publish Date: 2018-04-25
URL: WS-2018-0084
Step up your Open Source Security Game with WhiteSource here
Recursive object extending
path: /Buscador_de_Recetas/node_modules/.staging/deep-extend-a0f4df3e/package.json
Library home page: https://registry.npmjs.org/deep-extend/-/deep-extend-0.4.2.tgz
Dependency Hierarchy:
Versions of deep-extend before 0.5.1 are vulnerable to prototype pollution.
Publish Date: 2018-04-25
URL: WS-2018-0091
Step up your Open Source Security Game with WhiteSource here
Recursive object extending
path: /Buscador_de_Recetas/node_modules/.staging/deep-extend-a0f4df3e/package.json
Library home page: https://registry.npmjs.org/deep-extend/-/deep-extend-0.4.2.tgz
Dependency Hierarchy:
The utilities function in all versions <= 0.5.0 of the deep-extend node module can be tricked into modifying the prototype of Object when the attacker can control part of the structure passed to this function. This can let an attacker add or modify existing properties that will exist on all objects.
Publish Date: 2018-07-03
URL: CVE-2018-3750
Base Score Metrics:
Type: Change files
Origin: RetireJS/retire.js@6a71696
Release Date: 2018-05-09
Fix Resolution: Replace or update the following file: npmrepository.json
Step up your Open Source Security Game with WhiteSource here
small debugging utility
path: /Buscador_de_Recetas/node_modules/.staging/debug-c1d897ee/package.json
Library home page: https://registry.npmjs.org/debug/-/debug-2.6.8.tgz
Dependency Hierarchy:
The debug module is vulnerable to regular expression denial of service when untrusted user input is passed into the o formatter. It takes around 50k characters to block for 2 seconds making this a low severity issue.
Publish Date: 2018-06-07
URL: CVE-2017-16137
Base Score Metrics:
Type: Upgrade version
Origin: https://nodesecurity.io/advisories/534
Release Date: 2017-09-27
Fix Resolution: Version 2.x.x: Update to version 2.6.9 or later. Version 3.x.x: Update to version 3.1.0 or later.
Step up your Open Source Security Game with WhiteSource here
HTTP Hawk Authentication Scheme
path: /Buscador_de_Recetas/node_modules/.staging/hawk-89ad7424/package.json
Library home page: http://registry.npmjs.org/hawk/-/hawk-3.1.3.tgz
Dependency Hierarchy:
Hawk before 3.1.3 and 4.x before 4.1.1 allow remote attackers to cause a denial of service (CPU consumption or partial outage) via a long (1) header or (2) URI that is matched against an improper regular expression.
Publish Date: 2016-04-13
URL: CVE-2016-2515
Base Score Metrics:
Type: Upgrade version
Origin: https://nodesecurity.io/advisories/77
Release Date: 2016-01-19
Fix Resolution: Update to hawk version 4.1.1 or greater.
Step up your Open Source Security Game with WhiteSource here
General purpose crypto utilities
path: /Buscador_de_Recetas/node_modules/.staging/cryptiles-27cf0d6f/package.json
Library home page: http://registry.npmjs.org/cryptiles/-/cryptiles-2.0.5.tgz
Dependency Hierarchy:
Eran Hammer cryptiles version 4.1.1 earlier contains a CWE-331: Insufficient Entropy vulnerability in randomDigits() method that can result in An attacker is more likely to be able to brute force something that was supposed to be random.. This attack appear to be exploitable via Depends upon the calling application.. This vulnerability appears to have been fixed in 4.1.2.
Publish Date: 2018-07-09
URL: CVE-2018-1000620
Base Score Metrics:
Step up your Open Source Security Game with WhiteSource here
General purpose node utilities
path: /Buscador_de_Recetas/node_modules/.staging/hoek-0ebbc4f9/package.json
Library home page: http://registry.npmjs.org/hoek/-/hoek-2.16.3.tgz
Dependency Hierarchy:
hoek node module before 4.2.0 and 5.0.x before 5.0.3 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability via 'merge' and 'applyToDefaults' functions, which allows a malicious user to modify the prototype of "Object" via proto, causing the addition or modification of an existing property that will exist on all objects.
Publish Date: 2018-03-30
URL: CVE-2018-3728
Base Score Metrics:
Type: Change files
Origin: hapijs/hoek@623667e
Release Date: 2018-02-15
Fix Resolution: Replace or update the following files: index.js, index.js
Step up your Open Source Security Game with WhiteSource here
RFC6265 Cookies and Cookie Jar for node.js
path: /Buscador_de_Recetas/node_modules/.staging/tough-cookie-f84013e3/package.json
Library home page: https://registry.npmjs.org/tough-cookie/-/tough-cookie-2.3.2.tgz
Dependency Hierarchy:
A ReDoS (regular expression denial of service) flaw was found in the tough-cookie module before 2.3.3 for Node.js. An attacker that is able to make an HTTP request using a specially crafted cookie may cause the application to consume an excessive amount of CPU.
Publish Date: 2017-10-04
URL: CVE-2017-15010
Base Score Metrics:
Type: Upgrade version
Origin: https://nodesecurity.io/advisories/525
Release Date: 2017-09-21
Fix Resolution: Update to version 2.3.3 or later.
Step up your Open Source Security Game with WhiteSource here
Encode and decode streams into string streams
path: /Buscador_de_Recetas/node_modules/.staging/stringstream-1bc6eb44/package.json
Library home page: http://registry.npmjs.org/stringstream/-/stringstream-0.0.5.tgz
Dependency Hierarchy:
All versions of stringstream are vulnerable to out-of-bounds read as it allocates uninitialized Buffers when number is passed in input stream on Node.js 4.x and below.
Publish Date: 2018-05-16
URL: WS-2018-0103
Step up your Open Source Security Game with WhiteSource here
A declarative, efficient, and flexible JavaScript library for building user interfaces.
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
An Open Source Machine Learning Framework for Everyone
The Web framework for perfectionists with deadlines.
A PHP framework for web artisans
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
Some thing interesting about web. New door for the world.
A server is a program made to process requests and deliver data to clients.
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
Some thing interesting about visualization, use data art
Some thing interesting about game, make everyone happy.
We are working to build community through open source technology. NB: members must have two-factor auth.
Open source projects and samples from Microsoft.
Google ❤️ Open Source for everyone.
Alibaba Open Source for everyone
Data-Driven Documents codes.
China tencent open source team.