0.6.7 - security vulnerability
See original GitHub issueThe recent version of ember-component-css v0.6.7 seems to have a dependency with a security vulnerability. The vulnerability was introduced with v0.6.7. Previous versions seem to be unaffected.
Steps to reproduce
mkdir issue && cd issue
npm init
npm install --save-dev ember-component-css
npm audit
=== npm audit security report ===
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β Manual Review β
β Some vulnerabilities require your attention to resolve β
β β
β Visit https://go.npm.me/audit-guide for additional guidance β
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
βββββββββββββββββ¬βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β Low β Prototype Pollution β
βββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β Package β lodash β
βββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β Patched in β >=4.17.5 β
βββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β Dependency of β ember-component-css [dev] β
βββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β Path β ember-component-css > broccoli-replace > applause > lodash β
βββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ€
β More info β https://nodesecurity.io/advisories/577 β
βββββββββββββββββ΄βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
found 1 low severity vulnerability in 3275 scanned packages
1 vulnerability requires manual review. See the full report for details.
Issue Analytics
- State:
- Created 5 years ago
- Reactions:1
- Comments:9 (5 by maintainers)
Top Results From Across the Web
GNU Nano version 0.6.7 : Security vulnerabilities - CVE Details
Security vulnerabilities of GNU Nano version 0.6.7 List of cve security vulnerabilities related to this exact version. You can filter results by cvss...
Read more >geddy 0.6.7 vulnerabilities | Snyk - Snyk Vulnerability Database
Learn more about known geddy 0.6.7 vulnerabilities and licenses detected.
Read more >Vulnerabilities in Flatpak 0.6.7 - CyberSecurity Help
List of known vulnerabilities in Flatpak in version 0.6.7. ... Main Β· Vulnerability Database Β· Flatpak Β· Flatpak; 0.6.7. With exploit. With patchΒ ......
Read more >Security Policy Β· janeczku/calibre-web - GitHub
Fixed in Description CVE number
3rd July 2018 Guest access acts as a backdoor
V 0.6.7 Hardcoded secret key for sessions CVEβ2020β12627
V 0.6.13 CalibreβWeb Metadata...
Read more >Velociraptor Version 0.6.7: Better Offline Collection ... - Rapid7
Having asymmetric encryption improves security greatly because only the public key needs to be included in the collector configuration. DumpingΒ ...
Read more >Top Related Medium Post
No results found
Top Related StackOverflow Question
No results found
Troubleshoot Live Code
Lightrun enables developers to add logs, metrics and snapshots to live code - no restarts or redeploys required.
Start FreeTop Related Reddit Thread
No results found
Top Related Hackernoon Post
No results found
Top Related Tweet
No results found
Top Related Dev.to Post
No results found
Top Related Hashnode Post
No results found
Top GitHub Comments
π¦ ummβ¦ sorry. This has been COMPLETELY off my plate as of recently. I will look at this soon.
or just use a different broccoli plugin, or write a custom one