An automation triggered a pipeline warning
Found 119 vulnerabilities. An additional 0 vulnerabilities have been marked as unaffected.
Output from Automations
4 rules were checked:
If a new dependency is added where the license risk is at least medium
then notify all users in the group admins by email
✔️ The rule did not trigger. Manage rule
If there is a dependency where the license risk is at least high
then send a pipeline warning
✔️ The rule did not trigger. Manage rule
If a dependency contains a vulnerability which has not been marked as unaffected and which has not triggered this rule for this dependency before
then notify all users in the group admins by email
📤 The rule triggered for the following vulnerabilities, causing an email notification. Manage rule
If a dependency contains a vulnerability which has not been marked as unaffected
then send a pipeline warning
⚠️ The rule triggered for the following vulnerabilities, causing a pipeline warning. Manage rule
| Vulnerability |
CVSS2 |
CVSS3 |
Dependency |
Dependency Licenses |
| CVE-2023-26136 |
N/A |
9.8 |
tough-cookie (npm) |
BSD-3-Clause |
| CVE-2021-23369 |
7.5 |
9.8 |
handlebars (npm) |
MIT |
| CVE-2021-23440 |
7.5 |
9.8 |
set-value (npm) |
MIT |
| CVE-2022-37601 |
N/A |
9.8 |
loader-utils (npm) |
MIT |
| CVE-2023-42282 |
N/A |
9.8 |
ip (npm) |
MIT |
| CVE-2019-10746 |
7.5 |
9.8 |
mixin-deep (npm) |
MIT |
| debricked-233443 |
10 |
9.8 |
execa (npm) |
MIT |
| CVE-2021-3918 |
7.5 |
9.8 |
json-schema (npm) |
BSD-3-Clause |
| CVE-2023-45311 |
N/A |
9.8 |
fsevents (npm) |
MIT |
| CVE-2019-19919 |
7.5 |
9.8 |
handlebars (npm) |
MIT |
| CVE-2019-10747 |
7.5 |
9.8 |
set-value (npm) |
MIT |
| CVE-2021-23383 |
7.5 |
9.8 |
handlebars (npm) |
MIT |
| CVE-2022-2421 |
N/A |
9.8 |
socket.io-parser (npm) |
MIT |
| CVE-2022-29078 |
7.5 |
9.8 |
ejs (npm) |
Apache-2.0 |
| CVE-2021-31597 |
7.5 |
9.4 |
xmlhttprequest-ssl (npm) |
MIT |
| CVE-2019-10744 |
6.4 |
9.1 |
lodash (npm) |
MIT |
| CVE-2023-45133 |
N/A |
8.8 |
@babel/traverse (npm) |
MIT |
| CVE-2022-46175 |
N/A |
8.8 |
json5 (npm) |
MIT |
| CVE-2023-45133 |
N/A |
8.8 |
babel-traverse (npm) |
MIT |
| CVE-2021-37713 |
4.4 |
8.6 |
tar (npm) |
ISC |
| CVE-2021-37712 |
4.4 |
8.6 |
tar (npm) |
ISC |
| CVE-2021-37701 |
4.4 |
8.6 |
tar (npm) |
ISC |
| CVE-2024-29415 |
N/A |
8.1 |
ip (npm) |
MIT |
| CVE-2021-32803 |
5.8 |
8.1 |
tar (npm) |
ISC |
| CVE-2020-7660 |
6.8 |
8.1 |
serialize-javascript (npm) |
BSD-3-Clause |
| CVE-2021-32804 |
5.8 |
8.1 |
tar (npm) |
ISC |
| CVE-2020-28502 |
6.8 |
8.1 |
xmlhttprequest-ssl (npm) |
MIT |
| CVE-2019-20920 |
6.8 |
8.1 |
handlebars (npm) |
MIT |
| CVE-2021-43138 |
6.8 |
7.8 |
async (npm) |
MIT |
| CVE-2023-32695 |
N/A |
7.5 |
socket.io-parser (npm) |
MIT |
| CVE-2022-37620 |
N/A |
7.5 |
html-minifier (npm) |
MIT |
| CVE-2019-20922 |
7.8 |
7.5 |
handlebars (npm) |
MIT |
| CVE-2024-4068 |
N/A |
7.5 |
braces (npm) |
MIT |
| CVE-2019-20149 |
5 |
7.5 |
kind-of (npm) |
MIT |
| CVE-2020-26311 |
N/A |
7.5 |
useragent (npm) |
MIT |
| CVE-2022-24772 |
5 |
7.5 |
node-forge (npm) |
BSD-3-Clause, GPL-2.0-only |
| CVE-2022-25883 |
N/A |
7.5 |
semver (npm) |
ISC |
| CVE-2022-38900 |
N/A |
7.5 |
decode-uri-component (npm) |
MIT |
| CVE-2020-36049 |
5 |
7.5 |
socket.io-parser (npm) |
MIT |
| CVE-2020-36048 |
5 |
7.5 |
engine.io (npm) |
MIT |
| CVE-2021-27290 |
4.3 |
7.5 |
ssri (npm) |
ISC |
| CVE-2022-25758 |
5 |
7.5 |
scss-tokenizer (npm) |
MIT |
| CVE-2022-24771 |
5 |
7.5 |
node-forge (npm) |
BSD-3-Clause, GPL-2.0-only |
| CVE-2024-45590 |
N/A |
7.5 |
body-parser (npm) |
MIT |
| CVE-2022-3517 |
N/A |
7.5 |
minimatch (npm) |
ISC |
| CVE-2021-33623 |
5 |
7.5 |
trim-newlines (npm) |
MIT |
| CVE-2024-37890 |
N/A |
7.5 |
ws (npm) |
MIT |
| CVE-2021-3807 |
7.8 |
7.5 |
ansi-regex (npm) |
MIT |
| CVE-2024-21536 |
N/A |
7.5 |
http-proxy-middleware (npm) |
MIT |
| CVE-2024-21538 |
N/A |
7.5 |
cross-spawn (npm) |
MIT |
| CVE-2021-23382 |
5 |
7.5 |
postcss (npm) |
MIT |
| CVE-2021-23343 |
5 |
7.5 |
path-parse (npm) |
MIT |
| CVE-2022-24999 |
N/A |
7.5 |
qs (npm) |
BSD-3-Clause |
| CVE-2024-29180 |
N/A |
7.4 |
webpack-dev-middleware (npm) |
MIT |
| CVE-2020-8203 |
5.8 |
7.4 |
lodash (npm) |
MIT |
| CVE-2020-7788 |
7.5 |
7.3 |
ini (npm) |
ISC |
| CVE-2024-38355 |
N/A |
7.3 |
socket.io (npm) |
MIT |
| CVE-2022-48285 |
N/A |
7.3 |
jszip (npm) |
GPL-3.0-only, MIT |
| CVE-2020-7774 |
7.5 |
7.3 |
y18n (npm) |
ISC |
| CVE-2021-23337 |
6.5 |
7.2 |
lodash (npm) |
MIT |
| CVE-2022-0144 |
3.6 |
7.1 |
shelljs (npm) |
BSD-3-Clause |
| CVE-2022-41940 |
N/A |
6.5 |
engine.io (npm) |
MIT |
| CVE-2024-28863 |
N/A |
6.5 |
tar (npm) |
ISC |
| CVE-2022-38778 |
N/A |
6.5 |
decode-uri-component (npm) |
MIT |
| CVE-2024-36751 |
N/A |
6.5 |
parseuri (npm) |
MIT |
| CVE-2022-0155 |
4.3 |
6.5 |
follow-redirects (npm) |
MIT |
| CVE-2024-28849 |
N/A |
6.5 |
follow-redirects (npm) |
MIT |
| CVE-2021-23495 |
5.8 |
6.1 |
karma (npm) |
MIT |
| CVE-2023-26159 |
N/A |
6.1 |
follow-redirects (npm) |
MIT |
| CVE-2024-6531 |
N/A |
6.1 |
bootstrap (npm) |
MIT |
| CVE-2019-11358 |
4.3 |
6.1 |
jquery (npm) |
MIT |
| CVE-2020-11023 |
4.3 |
6.1 |
jquery (npm) |
MIT |
| CVE-2020-11022 |
4.3 |
6.1 |
jquery (npm) |
MIT |
| CVE-2022-0437 |
4.3 |
6.1 |
karma (npm) |
MIT |
| CVE-2022-0122 |
5.8 |
6.1 |
node-forge (npm) |
BSD-3-Clause, GPL-2.0-only |
| CVE-2023-28155 |
N/A |
6.1 |
request (npm) |
Apache-2.0 |
| CVE-2022-0536 |
4.3 |
5.9 |
follow-redirects (npm) |
MIT |
| CVE-2020-15366 |
6.8 |
5.6 |
ajv (npm) |
MIT |
| CVE-2022-21704 |
2.1 |
5.5 |
log4js (npm) |
Apache-2.0 |
| CVE-2021-4231 |
3.5 |
5.4 |
@angular/core (npm) |
MIT |
| CVE-2021-23362 |
5 |
5.3 |
hosted-git-info (npm) |
ISC |
| CVE-2023-44270 |
N/A |
5.3 |
postcss (npm) |
MIT |
| CVE-2017-16137 |
5 |
5.3 |
debug (npm) |
MIT |
| CVE-2020-24025 |
5 |
5.3 |
node-sass (npm) |
MIT |
| CVE-2022-24773 |
5 |
5.3 |
node-forge (npm) |
BSD-3-Clause, GPL-2.0-only |
| CVE-2024-4067 |
N/A |
5.3 |
micromatch (npm) |
MIT |
| CVE-2020-7608 |
4.6 |
5.3 |
yargs-parser (npm) |
ISC |
| CVE-2023-0842 |
N/A |
5.3 |
xml2js (npm) |
MIT |
| CVE-2021-23413 |
5 |
5.3 |
jszip (npm) |
GPL-3.0-only, MIT |
| CVE-2020-28500 |
5 |
5.3 |
lodash (npm) |
MIT |
| CVE-2019-16769 |
3.5 |
4.6 |
serialize-javascript (npm) |
BSD-3-Clause |
| CVE-2020-28481 |
4 |
4.3 |
socket.io (npm) |
MIT |
| CVE-2024-33883 |
N/A |
4 |
ejs (npm) |
Apache-2.0 |
| debricked-149699 |
N/A |
N/A |
js-yaml (npm) |
MIT |
| debricked-233849 |
N/A |
N/A |
js-yaml (npm) |
MIT |
| debricked-233850 |
N/A |
N/A |
js-yaml (npm) |
MIT |
| debricked-149654 |
N/A |
N/A |
https-proxy-agent (npm) |
MIT |
| debricked-234346 |
N/A |
N/A |
https-proxy-agent (npm) |
MIT |
| debricked-149694 |
N/A |
N/A |
js-yaml (npm) |
MIT |
| CVE-2024-47764 |
N/A |
N/A |
cookie (npm) |
MIT |
| debricked-149662 |
N/A |
N/A |
mem (npm) |
MIT |
| debricked-179671 |
N/A |
N/A |
node-forge (npm) |
BSD-3-Clause, GPL-2.0-only |
| debricked-234441 |
N/A |
N/A |
node-forge (npm) |
BSD-3-Clause, GPL-2.0-only |
| debricked-234440 |
N/A |
N/A |
node-forge (npm) |
BSD-3-Clause, GPL-2.0-only |
| debricked-233691 |
N/A |
N/A |
http-proxy (npm) |
MIT |
| debricked-180554 |
N/A |
N/A |
shelljs (npm) |
BSD-3-Clause |
| debricked-234531 |
N/A |
N/A |
shelljs (npm) |
BSD-3-Clause |
| debricked-149740 |
N/A |
N/A |
http-proxy (npm) |
MIT |
| debricked-233507 |
N/A |
N/A |
fsevents (npm) |
MIT |
| debricked-179669 |
N/A |
N/A |
node-forge (npm) |
BSD-3-Clause, GPL-2.0-only |
| debricked-234255 |
N/A |
N/A |
handlebars (npm) |
MIT |
| debricked-97165 |
N/A |
N/A |
lodash (npm) |
MIT |
| debricked-149739 |
N/A |
N/A |
yargs-parser (npm) |
ISC |
| debricked-149414 |
N/A |
N/A |
handlebars (npm) |
MIT |
| debricked-149661 |
N/A |
N/A |
handlebars (npm) |
MIT |
| debricked-149815 |
N/A |
N/A |
handlebars (npm) |
MIT |
| debricked-149816 |
N/A |
N/A |
handlebars (npm) |
MIT |
| debricked-155741 |
N/A |
N/A |
ini (npm) |
ISC |
| debricked-234226 |
N/A |
N/A |
mem (npm) |
MIT |
| debricked-149824 |
N/A |
N/A |
handlebars (npm) |
MIT |