question-mark
Stuck on an issue?

Lightrun Answers was designed to reduce the constant googling that comes with debugging 3rd party libraries. It collects links to all the places you might be looking at while hunting down a tough bug.

And, if you’re still stuck at the end, we’re happy to hop on a call to see how we can help out.

NSP Vulnerabilities

See original GitHub issue

Hi Guys

Im running nsp to check for vulnerabilities in my project and some have been reported for kue.

┌───────────────┬────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐
│               │ Regular Expression Denial of Service                                                                                               │
├───────────────┼────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤
│ Name          │ uglify-js                                                                                                                          │
├───────────────┼────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤
│ Installed     │ 2.2.5                                                                                                                              │
├───────────────┼────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤
│ Vulnerable    │ <2.6.0                                                                                                                             │
├───────────────┼────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤
│ Patched       │ >=2.6.0                                                                                                                            │
├───────────────┼────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤
│ Path          │ manbag@1.0.0 > kue@0.11.0 > jade@1.11.0 > transformers@2.1.0 > uglify-js@2.2.5                                                     │
├───────────────┼────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤
│ More Info     │ https://nodesecurity.io/advisories/48                                                                                              │
└───────────────┴────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘

┌───────────────┬────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐
│               │ Incorrect Handling of Non-Boolean Comparisons During Minification                                                                  │
├───────────────┼────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤
│ Name          │ uglify-js                                                                                                                          │
├───────────────┼────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤
│ Installed     │ 2.2.5                                                                                                                              │
├───────────────┼────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤
│ Vulnerable    │ <= 2.4.23                                                                                                                          │
├───────────────┼────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤
│ Patched       │ >= 2.4.24                                                                                                                          │
├───────────────┼────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤
│ Path          │ manbag@1.0.0 > kue@0.11.0 > jade@1.11.0 > transformers@2.1.0 > uglify-js@2.2.5                                                     │
├───────────────┼────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤
│ More Info     │ https://nodesecurity.io/advisories/39                                                                                              │
└───────────────┴────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘

Issue Analytics

  • State:closed
  • Created 7 years ago
  • Comments:7 (1 by maintainers)

github_iconTop GitHub Comments

1reaction
tianpcommented, Sep 20, 2016

Just come to this issue because NSP reason as well, please take a look at the @jborrey’s PR @behrad.

1reaction
jborreycommented, Aug 15, 2016

This PR should fix.

Read more comments on GitHub >

github_iconTop Results From Across the Web

nsp vulnerabilities | Snyk
version published direct vulnerabilities 3.2.1 15 Feb, 2018 0. C. 0. H. 0. M. 0. L 3.2.0 15 Feb, 2018 0. C. 0. H. 0....
Read more >
NSP Vulnerability Management
NSP business cloud services offer a proven system to make your transition easier ... Identify vulnerabilities on your network before they're attacked.
Read more >
High/medium nsp vulnerabilities for dependency ws and hoek
Similar to vulnerability issues in the past (here and here), we have 2 outstanding nsp vulnerabilities. Running nsp check produces the following ...
Read more >
Using Snyk, NSP and Retire.JS to Identify and Fix Vulnerable ...
JS to Identify and Fix Vulnerable Dependencies in your Node.js Applications ... nsp check Test for any known vulnerabilities.
Read more >
[c-nsp] Vulnerabilities in HTTP server on Catalyst Switches
archive at http://puck.nether.net/pipermail/cisco-nsp/. Curtis Doty ... vulnerabilities, I'd be inclined to agree with your security admin unless
Read more >

github_iconTop Related Medium Post

No results found

github_iconTop Related StackOverflow Question

No results found

github_iconTroubleshoot Live Code

Lightrun enables developers to add logs, metrics and snapshots to live code - no restarts or redeploys required.
Start Free

github_iconTop Related Reddit Thread

No results found

github_iconTop Related Hackernoon Post

No results found

github_iconTop Related Tweet

No results found

github_iconTop Related Dev.to Post

No results found

github_iconTop Related Hashnode Post

No results found