Movatterモバイル変換


[0]ホーム

URL:


Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
Appearance settings

[Snyk] Security upgrade org.webjars.npm:axios from 0.19.2 to 1.6.5#16

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to ourterms of service andprivacy statement. We’ll occasionally send you account related emails.

Already on GitHub?Sign in to your account

Open
mihneacristian wants to merge1 commit intomaster
base:master
Choose a base branch
Loading
fromsnyk-fix-4a5d393571d255200685f08438646d25

Conversation

@mihneacristian
Copy link
Owner

This PR was automatically created by Snyk using the credentials of a real user.


![snyk-top-banner](https://github.com/andygongea/OWASP-Benchmark/assets/818805/c518c423-16fe-447e-b67f-ad5a49b5d123)

Snyk has created this PR to fix 9 vulnerabilities in the maven dependencies of this project.

Snyk changed the following file(s):

  • pom.xml

Vulnerabilities that will be fixed with an upgrade:

IssueScoreUpgrade
high severityRegular Expression Denial of Service (ReDoS)
SNYK-JAVA-ORGWEBJARSNPM-1579272
  696  org.webjars.npm:axios:
0.19.2 ->1.6.5
Proof of Concept
high severityImproper Input Validation
SNYK-JAVA-ORGWEBJARSNPM-6146044
  686  org.webjars.npm:axios:
0.19.2 ->1.6.5
Proof of Concept
high severityCross-site Request Forgery (CSRF)
SNYK-JAVA-ORGWEBJARSNPM-6038587
  676  org.webjars.npm:axios:
0.19.2 ->1.6.5
Major version upgradeProof of Concept
medium severityInformation Exposure
SNYK-JAVA-ORGWEBJARSNPM-6444611
  646  org.webjars.npm:axios:
0.19.2 ->1.6.5
Proof of Concept
medium severityServer-Side Request Forgery (SSRF)
SNYK-JAVA-ORGWEBJARSNPM-1038256
  616  org.webjars.npm:axios:
0.19.2 ->1.6.5
Proof of Concept
high severityPrototype Pollution
SNYK-JAVA-ORGWEBJARSNPM-6146045
  589  org.webjars.npm:axios:
0.19.2 ->1.6.5
Major version upgradeNo Known Exploit
medium severityInformation Exposure
SNYK-JAVA-ORGWEBJARSNPM-2332182
  586  org.webjars.npm:axios:
0.19.2 ->1.6.5
Proof of Concept
medium severityRegular Expression Denial of Service (ReDoS)
SNYK-JAVA-ORGWEBJARSNPM-6124858
  586  org.webjars.npm:axios:
0.19.2 ->1.6.5
Major version upgradeProof of Concept
low severityInformation Exposure
SNYK-JAVA-ORGWEBJARSNPM-2396347
  344  org.webjars.npm:axios:
0.19.2 ->1.6.5
No Known Exploit

Important

  • Check the changes in this PR to ensure they won't cause issues with your project.
  • Max score is 1000. Note that the real score may have changed since the PR was raised.
  • This PR was automatically created by Snyk using the credentials of a real user.

Note:You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.

For more information:
🧐View latest project report
📜Customise PR templates
🛠Adjust project settings
📚Read about Snyk's upgrade logic


Learn how to fix vulnerabilities with free interactive lessons:

🦉Server-Side Request Forgery (SSRF)
🦉Regular Expression Denial of Service (ReDoS)
🦉Cross-site Request Forgery (CSRF)
🦉More lessons are available in Snyk Learn

Sign up for freeto join this conversation on GitHub. Already have an account?Sign in to comment

Reviewers

No reviews

Assignees

No one assigned

Labels

None yet

Projects

None yet

Milestone

No milestone

Development

Successfully merging this pull request may close these issues.

3 participants

@mihneacristian@snyk-bot

[8]ページ先頭

©2009-2025 Movatter.jp