FazBrowse GitHub Viewer | Trending |
URL:
| Home
Tools: [Download Repo ZIP]   [Original HTTPS Page]

Security: Known vulnerable dependencies (CVE-2022-23529, CVE-2023-3696, CVE-2024-43796, CVE-2022-31129) · Issue #60 · maitraysuthar/rest-api-nodejs-mongodb · GitHub

Security: Known vulnerable dependencies (CVE-2022-23529, CVE-2023-3696, CVE-2024-43796, CVE-2022-31129) #60

Description

Security Advisory

This project includes four dependencies with known critical and high-severity vulnerabilities.

1. jsonwebtoken@^8.5.1 — CVE-2022-23529 (Critical)

JWT verification bypass allowing token forgery.

2. mongoose@^5.7.6 — CVE-2023-3696 (Critical)

Prototype pollution via crafted query objects.

3. express@~4.16.0 — CVE-2024-43796 (Medium)

XSS via response.redirect() with unsanitized input.

4. moment@^2.24.0 — CVE-2022-31129 (High)

ReDoS when parsing user-supplied date strings.

Recommendation

Update affected dependencies in package.json to their patched versions.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions


    Back | FazBrowse Home | New Git URL