Update dependency express to v4.21.2 #3
Security Report
You have successfully remediated 4 vulnerabilities, but introduced 3 new vulnerabilities in this branch.
❌ New vulnerabilities:
CVE | Severity | CVSS Score | Vulnerable Library | Suggested Fix | Issue | Reachability |
---|---|---|---|---|---|---|
CVE-2024-45590Path to dependency file: /achilles-frontend/package.json Path to vulnerable library: /achilles-frontend/node_modules/body-parser/package.json,/baak-vizualization/node_modules/body-parser/package.json Dependency Hierarchy: -> webpack-dev-server-4.9.0.tgz (Root Library) -> express-4.18.1.tgz -> ❌ body-parser-1.20.0.tgz (Vulnerable Library) |
High | 7.5 | body-parser-1.20.0.tgz | Upgrade to version: body-parser - 1.20.3 | #42 | |
CVE-2024-43800Path to dependency file: /achilles-frontend/package.json Path to vulnerable library: /achilles-frontend/node_modules/serve-static/package.json,/baak-vizualization/node_modules/serve-static/package.json Dependency Hierarchy: -> webpack-dev-server-4.9.0.tgz (Root Library) -> express-4.18.1.tgz -> ❌ serve-static-1.15.0.tgz (Vulnerable Library) |
Medium | 5.0 | serve-static-1.15.0.tgz | Upgrade to version: serve-static - 1.16.0,2.1.0 | #42 | |
CVE-2024-43799Path to dependency file: /achilles-frontend/package.json Path to vulnerable library: /achilles-frontend/node_modules/send/package.json,/baak-vizualization/node_modules/send/package.json Dependency Hierarchy: -> webpack-dev-server-4.9.0.tgz (Root Library) -> express-4.18.1.tgz -> ❌ send-0.18.0.tgz (Vulnerable Library) |
Medium | 5.0 | send-0.18.0.tgz | Upgrade to version: send - 0.19.0 | #42 |
✔️ Remediated vulnerabilities:
CVE | Vulnerable Library |
---|---|
CVE-2024-47764 | cookie-0.4.0.tgz |
CVE-2024-45590 | body-parser-1.19.0.tgz |
CVE-2024-29041 | express-4.17.1.tgz |
CVE-2022-24999 | qs-6.7.0.tgz |
Base branch total remaining vulnerabilities: 75
Base branch commit: b2828e2e5760706da2e449bc8b11e5e95aab348e
Total libraries scanned: 1925
Scan token: 19c419f05dc141629880f157ca9e63e5