Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

react-scripts 4.3.0 vulnerabilities #11123

Closed
Nagaashwath opened this issue Jun 18, 2021 · 3 comments
Closed

react-scripts 4.3.0 vulnerabilities #11123

Nagaashwath opened this issue Jun 18, 2021 · 3 comments

Comments

@Nagaashwath
Copy link

after "npm install react-scripts 4.3.0" there are 4 high vulnerabilities

OS: windows 10 64 bit

Reproduction steps: -
execute "npm install react-scripts 4.3.0"

output: -found 8 vulnerabilities (4 moderate, 4 high) in XXX scanned packages
8 vulnerabilities require manual review. See the full report for details.


High Regular Expression Denial of Service

Package normalize-url

Patched in >=4.5.1 <5.0.0 || >=5.3.1 <6.0.0 || >=6.0.1

Patched in >=4.5.1 <5.0.0 || >=5.3.1 <6.0.0 || >=6.0.1

Dependency of react-scripts

Path react-scripts > optimize-css-assets-webpack-plugin > cssnano
> cssnano-preset-default > postcss-normalize-url >
normalize-url


High Regular Expression Denial of Service

Package normalize-url
Patched in >=4.5.1 <5.0.0 || >=5.3.1 <6.0.0 || >=6.0.1

Dependency of react-scripts

Path react-scripts > mini-css-extract-plugin > normalize-url


High Denial of Service

Package css-what

Patched in >=5.0.1

Dependency of react-scripts

Path react-scripts > optimize-css-assets-webpack-plugin > cssnano
> cssnano-preset-default > postcss-svgo > svgo > css-select
> css-what

@Davydx7
Copy link

Davydx7 commented Jun 20, 2021

Capture

@croraf
Copy link

croraf commented Jun 21, 2021

Can this be cosed in favor of: #11012 ?

@gaearon
Copy link
Contributor

gaearon commented Jul 7, 2021

#11174

@gaearon gaearon closed this as completed Jul 7, 2021
@facebook facebook locked as resolved and limited conversation to collaborators Jul 7, 2021
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Projects
None yet
Development

No branches or pull requests

4 participants