Skip to content

vuln: Prototype Pollution and ReDoS introduced via google-gax@0.15.0 #465

@stephenplusplus

Description

@stephenplusplus
Copied from original issue: googleapis/nodejs-datastore#69

@anishkny
March 16, 2018 12:06 AM

Snyk reports vulns:

  1. Prototype Pollution - Vulnerable module: hoek - Introduced through: google-gax@0.15.0
  2. Regular Expression Denial of Service (ReDoS) - Vulnerable module: protobufjs - Introduced through: google-gax@0.15.0

See: https://snyk.io/test/npm/@google-cloud/datastore

Environment details

  • OS: Any
  • Node.js version: Any
  • npm version: Any
  • @google-cloud/datastore version: 1.3.5

Steps to reproduce

N/A

Metadata

Metadata

Labels

🚨This issue needs some love.triage meI really want to be triaged.

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions