[Snyk] Fix for 5 vulnerabilities - #288
Conversation
The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-MULTER-17342512 - https://snyk.io/vuln/SNYK-JS-AXIOS-15252993 - https://snyk.io/vuln/SNYK-JS-AXIOS-17172681 - https://snyk.io/vuln/SNYK-JS-AXIOS-16298058 - https://snyk.io/vuln/SNYK-JS-AXIOS-16299923
|
This update includes two packages. The axios 0.27.2 → 0.32.0Risk: Medium This upgrade spans several versions that primarily backport security fixes from the 1.x branch. The key changes address vulnerabilities like prototype pollution, Server-Side Request Forgery (SSRF), and credential leakage. Breaking Change: Recommendation: multer 2.1.1 → 2.2.0Risk: Low This is a minor security update that patches two denial-of-service (DoS) vulnerabilities:
There are no breaking API changes in this version. The upgrade is recommended to improve security.
|
Snyk has created this PR to fix 5 vulnerabilities in the npm dependencies of this project.
Snyk changed the following file(s):
package.jsonpackage-lock.jsonVulnerabilities that will be fixed with an upgrade:
SNYK-JS-MULTER-17342512
SNYK-JS-AXIOS-15252993
SNYK-JS-AXIOS-17172681
SNYK-JS-AXIOS-16298058
SNYK-JS-AXIOS-16299923
Breaking Change Risk
Important
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open fix PRs.
For more information:
🧐 View latest project report
📜 Customise PR templates
🛠 Adjust project settings
📚 Read about Snyk's upgrade logic
Learn how to fix vulnerabilities with free interactive lessons:
🦉 Prototype Pollution
🦉 Uncontrolled Recursion