Skip to content

[Workspace]Refactor workspace form UI (#7133)

Mend for GitHub.com / WhiteSource Security Check failed Jul 12, 2024 in 14m 33s

Security Report

The Security Check found 19 vulnerabilities.

CVE Severity CVSS Score Vulnerable Library Suggested Fix Issue
WS-2017-3772

Vulnerable Source Files:

❌ /packages/osd-ui-framework/node_modules/underscore.string/unescapeHTML.js

High 7.5 juice-shopjuice-shop-14.5.1_node16_darwin_x64 Upgrade to version: underscore.string - 3.3.5 #4734
CVE-2024-39249

Path to dependency file: /package.json

Path to vulnerable library: /node_modules/async/package.json,/node_modules/grunt/node_modules/async/package.json,/node_modules/@osd/ui-framework/node_modules/async/package.json

Dependency Hierarchy:

-> @osd/plugin-generator-1.0.0.tgz (Root Library)

   -> ejs-3.1.10.tgz

     -> jake-10.8.5.tgz

       -> ❌ async-3.2.3.tgz (Vulnerable Library)

Medium 6.5 async-3.2.3.tgz #7155
CVE-2024-39249

Path to vulnerable library: /packages/osd-ui-framework/node_modules/async/dist/async.min.js

Dependency Hierarchy:

-> ❌ async-3.2.3.min.js (Vulnerable Library)

Medium 6.5 async-3.2.3.min.js #7155
CVE-2024-39249

Path to vulnerable library: /packages/osd-ui-framework/node_modules/async/dist/async.js

Dependency Hierarchy:

-> ❌ async-3.2.3.js (Vulnerable Library)

Medium 6.5 async-3.2.3.js #7155
CVE-2023-28155

Path to dependency file: /package.json

Path to vulnerable library: /node_modules/@cypress/request/package.json

Dependency Hierarchy:

-> cypress-9.5.4.tgz (Root Library)

   -> ❌ request-2.88.12.tgz (Vulnerable Library)

Medium 6.1 request-2.88.12.tgz Upgrade to version: @cypress/request - 3.0.0 #5893
CVE-2023-26487

Path to dependency file: /node_modules/leaflet-vega/demo/demo.html

Path to vulnerable library: /node_modules/leaflet-vega/demo/demo.html

Dependency Hierarchy:

-> ❌ vega-5.22.1.js (Vulnerable Library)

Medium 6.1 vega-5.22.1.js Upgrade to version: vega - 5.23.0, vega-functions - 5.13.1 #3525
CVE-2023-26486

Path to dependency file: /node_modules/leaflet-vega/demo/demo.html

Path to vulnerable library: /node_modules/leaflet-vega/demo/demo.html

Dependency Hierarchy:

-> ❌ vega-5.22.1.js (Vulnerable Library)

Medium 6.1 vega-5.22.1.js Upgrade to version: vega - 5.23.0, vega-functions - 5.13.1 #3526
CVE-2020-11023

Path to dependency file: /node_modules/javascript-natural-sort/unit-tests.html

Path to vulnerable library: /node_modules/javascript-natural-sort/unit-tests.html

Dependency Hierarchy:

-> ❌ jquery-1.11.1.js (Vulnerable Library)

Medium 6.1 jquery-1.11.1.js Upgrade to version: jquery - 3.5.0;jquery-rails - 4.4.0 #4732
CVE-2020-11022

Path to dependency file: /node_modules/javascript-natural-sort/unit-tests.html

Path to vulnerable library: /node_modules/javascript-natural-sort/unit-tests.html

Dependency Hierarchy:

-> ❌ jquery-1.11.1.js (Vulnerable Library)

Medium 6.1 jquery-1.11.1.js Upgrade to version: jQuery - 3.5.0 #4733
CVE-2019-8331

Path to dependency file: /node_modules/leaflet-draw/docs/examples/basic.html

Path to vulnerable library: /node_modules/leaflet-draw/docs/examples/basic.html

Dependency Hierarchy:

-> ❌ bootstrap-3.3.7.min.js (Vulnerable Library)

Medium 6.1 bootstrap-3.3.7.min.js Upgrade to version: bootstrap - 3.4.1,4.3.1;bootstrap-sass - 3.4.1,4.3.1 #4722
CVE-2019-11358

Path to dependency file: /node_modules/javascript-natural-sort/unit-tests.html

Path to vulnerable library: /node_modules/javascript-natural-sort/unit-tests.html

Dependency Hierarchy:

-> ❌ jquery-1.11.1.js (Vulnerable Library)

Medium 6.1 jquery-1.11.1.js Upgrade to version: jquery - 3.4.0 #4730
CVE-2018-20677

Path to dependency file: /node_modules/leaflet-draw/docs/examples/basic.html

Path to vulnerable library: /node_modules/leaflet-draw/docs/examples/basic.html

Dependency Hierarchy:

-> ❌ bootstrap-3.3.7.min.js (Vulnerable Library)

Medium 6.1 bootstrap-3.3.7.min.js Upgrade to version: bootstrap - 3.4.0 #4725
CVE-2018-20676

Path to dependency file: /node_modules/leaflet-draw/docs/examples/basic.html

Path to vulnerable library: /node_modules/leaflet-draw/docs/examples/basic.html

Dependency Hierarchy:

-> ❌ bootstrap-3.3.7.min.js (Vulnerable Library)

Medium 6.1 bootstrap-3.3.7.min.js Upgrade to version: bootstrap - 3.4.0 #4728
CVE-2018-14042

Path to dependency file: /node_modules/leaflet-draw/docs/examples/basic.html

Path to vulnerable library: /node_modules/leaflet-draw/docs/examples/basic.html

Dependency Hierarchy:

-> ❌ bootstrap-3.3.7.min.js (Vulnerable Library)

Medium 6.1 bootstrap-3.3.7.min.js Upgrade to version: bootstrap - 3.4.0,4.1.2 #4727
CVE-2016-10735

Path to dependency file: /node_modules/leaflet-draw/docs/examples/basic.html

Path to vulnerable library: /node_modules/leaflet-draw/docs/examples/basic.html

Dependency Hierarchy:

-> ❌ bootstrap-3.3.7.min.js (Vulnerable Library)

Medium 6.1 bootstrap-3.3.7.min.js Upgrade to version: bootstrap - 3.4.0, 4.0.0-beta.2 #4729
CVE-2015-9251

Path to dependency file: /node_modules/javascript-natural-sort/unit-tests.html

Path to vulnerable library: /node_modules/javascript-natural-sort/unit-tests.html

Dependency Hierarchy:

-> ❌ jquery-1.11.1.js (Vulnerable Library)

Medium 6.1 jquery-1.11.1.js Upgrade to version: jQuery - 3.0.0 #4736
CVE-2024-4067
Medium 5.3 juice-shopjuice-shop-15.2.0_node16_win32_x64 Upgrade to version: micromatch - 4.0.6 #6791
CVE-2023-44270

Path to dependency file: /package.json

Path to vulnerable library: /node_modules/postcss/package.json

Dependency Hierarchy:

-> ❌ postcss-8.4.12.tgz (Vulnerable Library)

Medium 5.3 postcss-8.4.12.tgz Upgrade to version: postcss - 8.4.31 #5178
CVE-2018-14040

Path to dependency file: /node_modules/leaflet-draw/docs/examples/basic.html

Path to vulnerable library: /node_modules/leaflet-draw/docs/examples/basic.html

Dependency Hierarchy:

-> ❌ bootstrap-3.3.7.min.js (Vulnerable Library)

Low 3.7 bootstrap-3.3.7.min.js Upgrade to version: org.webjars.npm:bootstrap:4.1.2,org.webjars:bootstrap:3.4.0 #4723

Total libraries scanned: 2557
Scan token: ebac56e50510495e907db15c58e4af47