audit-result.json 204 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485868788899091929394959697989910010110210310410510610710810911011111211311411511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614714814915015115215315415515615715815916016116216316416516616716816917017117217317417517617717817918018118218318418518618718818919019119219319419519619719819920020120220320420520620720820921021121221321421521621721821922022122222322422522622722822923023123223323423523623723823924024124224324424524624724824925025125225325425525625725825926026126226326426526626726826927027127227327427527627727827928028128228328428528628728828929029129229329429529629729829930030130230330430530630730830931031131231331431531631731831932032132232332432532632732832933033133233333433533633733833934034134234334434534634734834935035135235335435535635735835936036136236336436536636736836937037137237337437537637737837938038138238338438538638738838939039139239339439539639739839940040140240340440540640740840941041141241341441541641741841942042142242342442542642742842943043143243343443543643743843944044144244344444544644744844945045145245345445545645745845946046146246346446546646746846947047147247347447547647747847948048148248348448548648748848949049149249349449549649749849950050150250350450550650750850951051151251351451551651751851952052152252352452552652752852953053153253353453553653753853954054154254354454554654754854955055155255355455555655755855956056156256356456556656756856957057157257357457557657757857958058158258358458558658758858959059159259359459559659759859960060160260360460560660760860961061161261361461561661761861962062162262362462562662762862963063163263363463563663763863964064164264364464564664764864965065165265365465565665765865966066166266366466566666766866967067167267367467567667767867968068168268368468568668768868969069169269369469569669769869970070170270370470570670770870971071171271371471571671771871972072172272372472572672772872973073173273373473573673773873974074174274374474574674774874975075175275375475575675775875976076176276376476576676776876977077177277377477577677777877978078178278378478578678778878979079179279379479579679779879980080180280380480580680780880981081181281381481581681781881982082182282382482582682782882983083183283383483583683783883984084184284384484584684784884985085185285385485585685785885986086186286386486586686786886987087187287387487587687787887988088188288388488588688788888989089189289389489589689789889990090190290390490590690790890991091191291391491591691791891992092192292392492592692792892993093193293393493593693793893994094194294394494594694794894995095195295395495595695795895996096196296396496596696796896997097197297397497597697797897998098198298398498598698798898999099199299399499599699799899910001001100210031004100510061007100810091010101110121013101410151016101710181019102010211022102310241025102610271028102910301031103210331034103510361037103810391040104110421043104410451046104710481049105010511052105310541055105610571058105910601061106210631064106510661067106810691070107110721073107410751076107710781079108010811082108310841085108610871088108910901091109210931094109510961097109810991100110111021103110411051106110711081109111011111112111311141115111611171118111911201121112211231124112511261127112811291130113111321133113411351136113711381139114011411142114311441145114611471148114911501151115211531154115511561157115811591160116111621163116411651166116711681169117011711172117311741175117611771178117911801181118211831184118511861187118811891190119111921193119411951196119711981199120012011202120312041205120612071208120912101211121212131214121512161217121812191220122112221223122412251226122712281229123012311232123312341235123612371238123912401241124212431244124512461247124812491250125112521253125412551256125712581259126012611262126312641265126612671268126912701271127212731274127512761277127812791280128112821283128412851286128712881289129012911292129312941295129612971298129913001301130213031304130513061307130813091310131113121313131413151316131713181319132013211322132313241325132613271328132913301331133213331334133513361337133813391340134113421343134413451346134713481349135013511352135313541355135613571358135913601361136213631364136513661367136813691370137113721373137413751376137713781379138013811382138313841385138613871388138913901391139213931394139513961397139813991400140114021403140414051406140714081409141014111412141314141415141614171418141914201421142214231424142514261427142814291430143114321433143414351436143714381439144014411442144314441445144614471448144914501451145214531454145514561457145814591460146114621463146414651466146714681469147014711472147314741475147614771478147914801481148214831484148514861487148814891490149114921493149414951496149714981499150015011502150315041505150615071508150915101511151215131514151515161517151815191520152115221523152415251526152715281529153015311532153315341535153615371538153915401541154215431544154515461547154815491550155115521553155415551556155715581559156015611562156315641565156615671568156915701571157215731574157515761577157815791580158115821583158415851586158715881589159015911592159315941595159615971598159916001601160216031604160516061607160816091610161116121613161416151616161716181619162016211622162316241625162616271628162916301631163216331634163516361637163816391640164116421643164416451646164716481649165016511652165316541655165616571658165916601661166216631664166516661667166816691670167116721673167416751676167716781679168016811682168316841685168616871688168916901691169216931694169516961697169816991700170117021703170417051706170717081709171017111712171317141715171617171718171917201721172217231724172517261727172817291730173117321733173417351736173717381739174017411742174317441745174617471748174917501751175217531754175517561757175817591760176117621763176417651766176717681769177017711772177317741775177617771778177917801781178217831784178517861787178817891790179117921793179417951796179717981799180018011802180318041805180618071808180918101811181218131814181518161817181818191820182118221823182418251826182718281829183018311832183318341835183618371838183918401841184218431844184518461847184818491850185118521853185418551856185718581859186018611862186318641865186618671868186918701871187218731874187518761877187818791880188118821883188418851886188718881889189018911892189318941895189618971898189919001901190219031904190519061907190819091910191119121913191419151916191719181919192019211922192319241925192619271928192919301931193219331934
  1. {
  2. "@intervolga/optimize-cssnano-plugin": {
  3. "name": "@intervolga/optimize-cssnano-plugin",
  4. "severity": "moderate",
  5. "isDirect": false,
  6. "via": [
  7. "cssnano",
  8. "cssnano-preset-default",
  9. "postcss"
  10. ],
  11. "effects": [
  12. ],
  13. "range": "*",
  14. "nodes": [
  15. "node_modules/@intervolga/optimize-cssnano-plugin"
  16. ],
  17. "fixAvailable": true
  18. },
  19. "@riophae/vue-treeselect": {
  20. "name": "@riophae/vue-treeselect",
  21. "severity": "low",
  22. "isDirect": true,
  23. "via": [
  24. "vue"
  25. ],
  26. "effects": [
  27. ],
  28. "range": "*",
  29. "nodes": [
  30. "node_modules/@riophae/vue-treeselect"
  31. ],
  32. "fixAvailable": false
  33. },
  34. "@types/webpack-dev-server": {
  35. "name": "@types/webpack-dev-server",
  36. "severity": "high",
  37. "isDirect": false,
  38. "via": [
  39. "http-proxy-middleware"
  40. ],
  41. "effects": [
  42. ],
  43. "range": "3.11.2 - 4.0.3",
  44. "nodes": [
  45. "node_modules/@types/webpack-dev-server"
  46. ],
  47. "fixAvailable": true
  48. },
  49. "@vue/cli-plugin-babel": {
  50. "name": "@vue/cli-plugin-babel",
  51. "severity": "moderate",
  52. "isDirect": true,
  53. "via": [
  54. "@vue/cli-service",
  55. "@vue/cli-shared-utils"
  56. ],
  57. "effects": [
  58. ],
  59. "range": "\u003e=3.4.0",
  60. "nodes": [
  61. "node_modules/@vue/cli-plugin-babel"
  62. ],
  63. "fixAvailable": {
  64. "name": "@vue/cli-plugin-babel",
  65. "version": "5.0.9",
  66. "isSemVerMajor": true
  67. }
  68. },
  69. "@vue/cli-plugin-eslint": {
  70. "name": "@vue/cli-plugin-eslint",
  71. "severity": "high",
  72. "isDirect": true,
  73. "via": [
  74. "@vue/cli-service",
  75. "@vue/cli-shared-utils",
  76. "inquirer",
  77. "yorkie"
  78. ],
  79. "effects": [
  80. ],
  81. "range": "*",
  82. "nodes": [
  83. "node_modules/@vue/cli-plugin-eslint"
  84. ],
  85. "fixAvailable": {
  86. "name": "@vue/cli-plugin-eslint",
  87. "version": "5.0.9",
  88. "isSemVerMajor": true
  89. }
  90. },
  91. "@vue/cli-plugin-router": {
  92. "name": "@vue/cli-plugin-router",
  93. "severity": "moderate",
  94. "isDirect": false,
  95. "via": [
  96. "@vue/cli-service",
  97. "@vue/cli-shared-utils"
  98. ],
  99. "effects": [
  100. "@vue/cli-service"
  101. ],
  102. "range": "*",
  103. "nodes": [
  104. "node_modules/@vue/cli-plugin-router"
  105. ],
  106. "fixAvailable": {
  107. "name": "@vue/cli-plugin-babel",
  108. "version": "5.0.9",
  109. "isSemVerMajor": true
  110. }
  111. },
  112. "@vue/cli-plugin-vuex": {
  113. "name": "@vue/cli-plugin-vuex",
  114. "severity": "moderate",
  115. "isDirect": false,
  116. "via": [
  117. "@vue/cli-service"
  118. ],
  119. "effects": [
  120. "@vue/cli-service"
  121. ],
  122. "range": "*",
  123. "nodes": [
  124. "node_modules/@vue/cli-plugin-vuex"
  125. ],
  126. "fixAvailable": {
  127. "name": "@vue/cli-plugin-babel",
  128. "version": "5.0.9",
  129. "isSemVerMajor": true
  130. }
  131. },
  132. "@vue/cli-service": {
  133. "name": "@vue/cli-service",
  134. "severity": "critical",
  135. "isDirect": true,
  136. "via": [
  137. "@intervolga/optimize-cssnano-plugin",
  138. "@vue/cli-plugin-router",
  139. "@vue/cli-plugin-vuex",
  140. "@vue/cli-shared-utils",
  141. "@vue/component-compiler-utils",
  142. "autoprefixer",
  143. "css-loader",
  144. "cssnano",
  145. "html-webpack-plugin",
  146. "postcss-loader",
  147. "vue-loader",
  148. "vue-template-compiler",
  149. "webpack-dev-server"
  150. ],
  151. "effects": [
  152. "@vue/cli-plugin-babel",
  153. "@vue/cli-plugin-eslint",
  154. "@vue/cli-plugin-router",
  155. "@vue/cli-plugin-vuex"
  156. ],
  157. "range": "*",
  158. "nodes": [
  159. "node_modules/@vue/cli-service"
  160. ],
  161. "fixAvailable": {
  162. "name": "@vue/cli-plugin-babel",
  163. "version": "5.0.9",
  164. "isSemVerMajor": true
  165. }
  166. },
  167. "@vue/cli-shared-utils": {
  168. "name": "@vue/cli-shared-utils",
  169. "severity": "moderate",
  170. "isDirect": false,
  171. "via": [
  172. "request"
  173. ],
  174. "effects": [
  175. "@vue/cli-plugin-babel",
  176. "@vue/cli-plugin-eslint",
  177. "@vue/cli-plugin-router"
  178. ],
  179. "range": "\u003c=4.5.19",
  180. "nodes": [
  181. "node_modules/@vue/cli-shared-utils"
  182. ],
  183. "fixAvailable": {
  184. "name": "@vue/cli-plugin-eslint",
  185. "version": "5.0.9",
  186. "isSemVerMajor": true
  187. }
  188. },
  189. "@vue/component-compiler-utils": {
  190. "name": "@vue/component-compiler-utils",
  191. "severity": "moderate",
  192. "isDirect": false,
  193. "via": [
  194. "postcss"
  195. ],
  196. "effects": [
  197. "@vue/cli-service",
  198. "vue-loader"
  199. ],
  200. "range": "*",
  201. "nodes": [
  202. "node_modules/@vue/component-compiler-utils"
  203. ],
  204. "fixAvailable": {
  205. "name": "@vue/cli-plugin-babel",
  206. "version": "5.0.9",
  207. "isSemVerMajor": true
  208. }
  209. },
  210. "autoprefixer": {
  211. "name": "autoprefixer",
  212. "severity": "moderate",
  213. "isDirect": false,
  214. "via": [
  215. "postcss"
  216. ],
  217. "effects": [
  218. ],
  219. "range": "1.0.20131222 - 9.8.8",
  220. "nodes": [
  221. "node_modules/autoprefixer"
  222. ],
  223. "fixAvailable": true
  224. },
  225. "bonjour": {
  226. "name": "bonjour",
  227. "severity": "high",
  228. "isDirect": false,
  229. "via": [
  230. "multicast-dns"
  231. ],
  232. "effects": [
  233. "webpack-dev-server"
  234. ],
  235. "range": "\u003e=3.3.1",
  236. "nodes": [
  237. "node_modules/bonjour"
  238. ],
  239. "fixAvailable": true
  240. },
  241. "cross-spawn": {
  242. "name": "cross-spawn",
  243. "severity": "high",
  244. "isDirect": false,
  245. "via": [
  246. {
  247. "source": 1104663,
  248. "name": "cross-spawn",
  249. "dependency": "cross-spawn",
  250. "title": "Regular Expression Denial of Service (ReDoS) in cross-spawn",
  251. "url": "https://github.com/advisories/GHSA-3xgq-45jj-v275",
  252. "severity": "high",
  253. "cwe": [
  254. "CWE-1333"
  255. ],
  256. "cvss": {
  257. "score": 7.5,
  258. "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
  259. },
  260. "range": "\u003c6.0.6"
  261. }
  262. ],
  263. "effects": [
  264. "execa"
  265. ],
  266. "range": "\u003c6.0.6",
  267. "nodes": [
  268. "node_modules/yorkie/node_modules/cross-spawn"
  269. ],
  270. "fixAvailable": {
  271. "name": "@vue/cli-plugin-eslint",
  272. "version": "5.0.9",
  273. "isSemVerMajor": true
  274. }
  275. },
  276. "css-declaration-sorter": {
  277. "name": "css-declaration-sorter",
  278. "severity": "moderate",
  279. "isDirect": false,
  280. "via": [
  281. "postcss"
  282. ],
  283. "effects": [
  284. ],
  285. "range": "\u003c=5.1.2",
  286. "nodes": [
  287. "node_modules/css-declaration-sorter"
  288. ],
  289. "fixAvailable": true
  290. },
  291. "css-loader": {
  292. "name": "css-loader",
  293. "severity": "moderate",
  294. "isDirect": false,
  295. "via": [
  296. "icss-utils",
  297. "postcss",
  298. "postcss-modules-extract-imports",
  299. "postcss-modules-local-by-default",
  300. "postcss-modules-scope",
  301. "postcss-modules-values"
  302. ],
  303. "effects": [
  304. "@vue/cli-service"
  305. ],
  306. "range": "0.15.0 - 4.3.0",
  307. "nodes": [
  308. "node_modules/css-loader"
  309. ],
  310. "fixAvailable": {
  311. "name": "@vue/cli-plugin-babel",
  312. "version": "5.0.9",
  313. "isSemVerMajor": true
  314. }
  315. },
  316. "cssnano": {
  317. "name": "cssnano",
  318. "severity": "moderate",
  319. "isDirect": false,
  320. "via": [
  321. "cssnano-preset-default",
  322. "postcss"
  323. ],
  324. "effects": [
  325. "@intervolga/optimize-cssnano-plugin",
  326. "@vue/cli-service"
  327. ],
  328. "range": "\u003c=4.1.11",
  329. "nodes": [
  330. "node_modules/cssnano"
  331. ],
  332. "fixAvailable": {
  333. "name": "@vue/cli-plugin-babel",
  334. "version": "5.0.9",
  335. "isSemVerMajor": true
  336. }
  337. },
  338. "cssnano-preset-default": {
  339. "name": "cssnano-preset-default",
  340. "severity": "moderate",
  341. "isDirect": false,
  342. "via": [
  343. "css-declaration-sorter",
  344. "cssnano-util-raw-cache",
  345. "postcss",
  346. "postcss-calc",
  347. "postcss-colormin",
  348. "postcss-convert-values",
  349. "postcss-discard-comments",
  350. "postcss-discard-duplicates",
  351. "postcss-discard-empty",
  352. "postcss-discard-overridden",
  353. "postcss-merge-longhand",
  354. "postcss-merge-rules",
  355. "postcss-minify-font-values",
  356. "postcss-minify-gradients",
  357. "postcss-minify-params",
  358. "postcss-minify-selectors",
  359. "postcss-normalize-charset",
  360. "postcss-normalize-display-values",
  361. "postcss-normalize-positions",
  362. "postcss-normalize-repeat-style",
  363. "postcss-normalize-string",
  364. "postcss-normalize-timing-functions",
  365. "postcss-normalize-unicode",
  366. "postcss-normalize-url",
  367. "postcss-normalize-whitespace",
  368. "postcss-ordered-values",
  369. "postcss-reduce-initial",
  370. "postcss-reduce-transforms",
  371. "postcss-svgo",
  372. "postcss-unique-selectors"
  373. ],
  374. "effects": [
  375. "cssnano"
  376. ],
  377. "range": "\u003c=4.0.8",
  378. "nodes": [
  379. "node_modules/cssnano-preset-default"
  380. ],
  381. "fixAvailable": {
  382. "name": "@vue/cli-plugin-babel",
  383. "version": "5.0.9",
  384. "isSemVerMajor": true
  385. }
  386. },
  387. "cssnano-util-raw-cache": {
  388. "name": "cssnano-util-raw-cache",
  389. "severity": "moderate",
  390. "isDirect": false,
  391. "via": [
  392. "postcss"
  393. ],
  394. "effects": [
  395. ],
  396. "range": "*",
  397. "nodes": [
  398. "node_modules/cssnano-util-raw-cache"
  399. ],
  400. "fixAvailable": true
  401. },
  402. "dns-packet": {
  403. "name": "dns-packet",
  404. "severity": "high",
  405. "isDirect": false,
  406. "via": [
  407. "ip"
  408. ],
  409. "effects": [
  410. "multicast-dns"
  411. ],
  412. "range": "\u003c=5.2.4",
  413. "nodes": [
  414. "node_modules/dns-packet"
  415. ],
  416. "fixAvailable": true
  417. },
  418. "element-ui": {
  419. "name": "element-ui",
  420. "severity": "low",
  421. "isDirect": true,
  422. "via": [
  423. "vue"
  424. ],
  425. "effects": [
  426. ],
  427. "range": "\u003e=1.0.0-rc.1",
  428. "nodes": [
  429. "node_modules/element-ui"
  430. ],
  431. "fixAvailable": {
  432. "name": "element-ui",
  433. "version": "0.2.6",
  434. "isSemVerMajor": true
  435. }
  436. },
  437. "eslint": {
  438. "name": "eslint",
  439. "severity": "low",
  440. "isDirect": true,
  441. "via": [
  442. "inquirer"
  443. ],
  444. "effects": [
  445. ],
  446. "range": "4.0.0-alpha.0 - 7.2.0",
  447. "nodes": [
  448. "node_modules/eslint"
  449. ],
  450. "fixAvailable": {
  451. "name": "eslint",
  452. "version": "9.39.1",
  453. "isSemVerMajor": true
  454. }
  455. },
  456. "execa": {
  457. "name": "execa",
  458. "severity": "high",
  459. "isDirect": false,
  460. "via": [
  461. "cross-spawn"
  462. ],
  463. "effects": [
  464. "yorkie"
  465. ],
  466. "range": "0.5.0 - 0.9.0",
  467. "nodes": [
  468. "node_modules/yorkie/node_modules/execa"
  469. ],
  470. "fixAvailable": {
  471. "name": "@vue/cli-plugin-eslint",
  472. "version": "5.0.9",
  473. "isSemVerMajor": true
  474. }
  475. },
  476. "external-editor": {
  477. "name": "external-editor",
  478. "severity": "low",
  479. "isDirect": false,
  480. "via": [
  481. "tmp"
  482. ],
  483. "effects": [
  484. "inquirer"
  485. ],
  486. "range": "\u003e=1.1.1",
  487. "nodes": [
  488. "node_modules/external-editor"
  489. ],
  490. "fixAvailable": {
  491. "name": "@vue/cli-plugin-eslint",
  492. "version": "5.0.9",
  493. "isSemVerMajor": true
  494. }
  495. },
  496. "form-data": {
  497. "name": "form-data",
  498. "severity": "critical",
  499. "isDirect": false,
  500. "via": [
  501. {
  502. "source": 1109540,
  503. "name": "form-data",
  504. "dependency": "form-data",
  505. "title": "form-data uses unsafe random function in form-data for choosing boundary",
  506. "url": "https://github.com/advisories/GHSA-fjxv-7rqg-78g4",
  507. "severity": "critical",
  508. "cwe": [
  509. "CWE-330"
  510. ],
  511. "cvss": {
  512. "score": 0,
  513. "vectorString": null
  514. },
  515. "range": "\u003c2.5.4"
  516. }
  517. ],
  518. "effects": [
  519. "request"
  520. ],
  521. "range": "\u003c2.5.4",
  522. "nodes": [
  523. "node_modules/request/node_modules/form-data"
  524. ],
  525. "fixAvailable": {
  526. "name": "@vue/cli-plugin-eslint",
  527. "version": "5.0.9",
  528. "isSemVerMajor": true
  529. }
  530. },
  531. "html-minifier": {
  532. "name": "html-minifier",
  533. "severity": "high",
  534. "isDirect": false,
  535. "via": [
  536. {
  537. "source": 1105440,
  538. "name": "html-minifier",
  539. "dependency": "html-minifier",
  540. "title": "kangax html-minifier REDoS vulnerability",
  541. "url": "https://github.com/advisories/GHSA-pfq8-rq6v-vf5m",
  542. "severity": "high",
  543. "cwe": [
  544. "CWE-400",
  545. "CWE-1333"
  546. ],
  547. "cvss": {
  548. "score": 7.5,
  549. "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
  550. },
  551. "range": "\u003c=4.0.0"
  552. }
  553. ],
  554. "effects": [
  555. "html-webpack-plugin"
  556. ],
  557. "range": "*",
  558. "nodes": [
  559. "node_modules/html-minifier"
  560. ],
  561. "fixAvailable": {
  562. "name": "@vue/cli-plugin-babel",
  563. "version": "5.0.9",
  564. "isSemVerMajor": true
  565. }
  566. },
  567. "html-webpack-plugin": {
  568. "name": "html-webpack-plugin",
  569. "severity": "critical",
  570. "isDirect": false,
  571. "via": [
  572. "html-minifier",
  573. "loader-utils"
  574. ],
  575. "effects": [
  576. "@vue/cli-service",
  577. "svg-sprite-loader"
  578. ],
  579. "range": "1.4.0 - 4.0.0-beta.14",
  580. "nodes": [
  581. "node_modules/@vue/cli-service/node_modules/html-webpack-plugin",
  582. "node_modules/svg-sprite-loader/node_modules/html-webpack-plugin"
  583. ],
  584. "fixAvailable": {
  585. "name": "@vue/cli-plugin-babel",
  586. "version": "5.0.9",
  587. "isSemVerMajor": true
  588. }
  589. },
  590. "http-proxy-middleware": {
  591. "name": "http-proxy-middleware",
  592. "severity": "high",
  593. "isDirect": false,
  594. "via": [
  595. {
  596. "source": 1100223,
  597. "name": "http-proxy-middleware",
  598. "dependency": "http-proxy-middleware",
  599. "title": "Denial of service in http-proxy-middleware",
  600. "url": "https://github.com/advisories/GHSA-c7qv-q95q-8v27",
  601. "severity": "high",
  602. "cwe": [
  603. "CWE-400"
  604. ],
  605. "cvss": {
  606. "score": 7.5,
  607. "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
  608. },
  609. "range": "\u003c2.0.7"
  610. },
  611. {
  612. "source": 1104105,
  613. "name": "http-proxy-middleware",
  614. "dependency": "http-proxy-middleware",
  615. "title": "http-proxy-middleware allows fixRequestBody to proceed even if bodyParser has failed",
  616. "url": "https://github.com/advisories/GHSA-9gqv-wp59-fq42",
  617. "severity": "moderate",
  618. "cwe": [
  619. "CWE-754"
  620. ],
  621. "cvss": {
  622. "score": 4,
  623. "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N"
  624. },
  625. "range": "\u003e=1.3.0 \u003c2.0.9"
  626. },
  627. {
  628. "source": 1104106,
  629. "name": "http-proxy-middleware",
  630. "dependency": "http-proxy-middleware",
  631. "title": "http-proxy-middleware can call writeBody twice because \"else if\" is not used",
  632. "url": "https://github.com/advisories/GHSA-4www-5p9h-95mh",
  633. "severity": "moderate",
  634. "cwe": [
  635. "CWE-670"
  636. ],
  637. "cvss": {
  638. "score": 4,
  639. "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:L"
  640. },
  641. "range": "\u003e=1.3.0 \u003c2.0.8"
  642. }
  643. ],
  644. "effects": [
  645. "@types/webpack-dev-server",
  646. "webpack-dev-server"
  647. ],
  648. "range": "\u003c=2.0.8",
  649. "nodes": [
  650. "node_modules/http-proxy-middleware",
  651. "node_modules/webpack-dev-server/node_modules/http-proxy-middleware"
  652. ],
  653. "fixAvailable": true
  654. },
  655. "icss-utils": {
  656. "name": "icss-utils",
  657. "severity": "moderate",
  658. "isDirect": false,
  659. "via": [
  660. "postcss"
  661. ],
  662. "effects": [
  663. "css-loader",
  664. "postcss-modules-local-by-default",
  665. "postcss-modules-values"
  666. ],
  667. "range": "\u003c=4.1.1",
  668. "nodes": [
  669. "node_modules/icss-utils"
  670. ],
  671. "fixAvailable": {
  672. "name": "@vue/cli-plugin-babel",
  673. "version": "5.0.9",
  674. "isSemVerMajor": true
  675. }
  676. },
  677. "inquirer": {
  678. "name": "inquirer",
  679. "severity": "low",
  680. "isDirect": false,
  681. "via": [
  682. "external-editor"
  683. ],
  684. "effects": [
  685. "@vue/cli-plugin-eslint",
  686. "eslint"
  687. ],
  688. "range": "3.0.0 - 8.2.6 || 9.0.0 - 9.3.7",
  689. "nodes": [
  690. "node_modules/inquirer"
  691. ],
  692. "fixAvailable": {
  693. "name": "@vue/cli-plugin-eslint",
  694. "version": "5.0.9",
  695. "isSemVerMajor": true
  696. }
  697. },
  698. "ip": {
  699. "name": "ip",
  700. "severity": "high",
  701. "isDirect": false,
  702. "via": [
  703. {
  704. "source": 1101851,
  705. "name": "ip",
  706. "dependency": "ip",
  707. "title": "ip SSRF improper categorization in isPublic",
  708. "url": "https://github.com/advisories/GHSA-2p57-rm9w-gvfp",
  709. "severity": "high",
  710. "cwe": [
  711. "CWE-918"
  712. ],
  713. "cvss": {
  714. "score": 8.1,
  715. "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"
  716. },
  717. "range": "\u003c=2.0.1"
  718. }
  719. ],
  720. "effects": [
  721. "dns-packet",
  722. "webpack-dev-server"
  723. ],
  724. "range": "*",
  725. "nodes": [
  726. "node_modules/ip"
  727. ],
  728. "fixAvailable": true
  729. },
  730. "json5": {
  731. "name": "json5",
  732. "severity": "high",
  733. "isDirect": false,
  734. "via": [
  735. {
  736. "source": 1096543,
  737. "name": "json5",
  738. "dependency": "json5",
  739. "title": "Prototype Pollution in JSON5 via Parse Method",
  740. "url": "https://github.com/advisories/GHSA-9c47-m6qq-7p4h",
  741. "severity": "high",
  742. "cwe": [
  743. "CWE-1321"
  744. ],
  745. "cvss": {
  746. "score": 7.1,
  747. "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:H"
  748. },
  749. "range": "\u003c1.0.2"
  750. }
  751. ],
  752. "effects": [
  753. "loader-utils"
  754. ],
  755. "range": "\u003c1.0.2",
  756. "nodes": [
  757. "node_modules/@vue/cli-service/node_modules/json5",
  758. "node_modules/svg-sprite-loader/node_modules/html-webpack-plugin/node_modules/json5"
  759. ],
  760. "fixAvailable": {
  761. "name": "@vue/cli-plugin-babel",
  762. "version": "5.0.9",
  763. "isSemVerMajor": true
  764. }
  765. },
  766. "loader-utils": {
  767. "name": "loader-utils",
  768. "severity": "critical",
  769. "isDirect": false,
  770. "via": [
  771. {
  772. "source": 1094088,
  773. "name": "loader-utils",
  774. "dependency": "loader-utils",
  775. "title": "Prototype pollution in webpack loader-utils",
  776. "url": "https://github.com/advisories/GHSA-76p3-8jx3-jpfq",
  777. "severity": "critical",
  778. "cwe": [
  779. "CWE-1321"
  780. ],
  781. "cvss": {
  782. "score": 9.8,
  783. "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"
  784. },
  785. "range": "\u003c1.4.1"
  786. },
  787. "json5"
  788. ],
  789. "effects": [
  790. "html-webpack-plugin"
  791. ],
  792. "range": "\u003c=1.4.0",
  793. "nodes": [
  794. "node_modules/@vue/cli-service/node_modules/loader-utils",
  795. "node_modules/svg-sprite-loader/node_modules/html-webpack-plugin/node_modules/loader-utils"
  796. ],
  797. "fixAvailable": {
  798. "name": "@vue/cli-plugin-babel",
  799. "version": "5.0.9",
  800. "isSemVerMajor": true
  801. }
  802. },
  803. "lodash": {
  804. "name": "lodash",
  805. "severity": "critical",
  806. "isDirect": false,
  807. "via": [
  808. {
  809. "source": 1106913,
  810. "name": "lodash",
  811. "dependency": "lodash",
  812. "title": "Command Injection in lodash",
  813. "url": "https://github.com/advisories/GHSA-35jh-r3h4-6jhm",
  814. "severity": "high",
  815. "cwe": [
  816. "CWE-77",
  817. "CWE-94"
  818. ],
  819. "cvss": {
  820. "score": 7.2,
  821. "vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"
  822. },
  823. "range": "\u003c4.17.21"
  824. },
  825. {
  826. "source": 1106918,
  827. "name": "lodash",
  828. "dependency": "lodash",
  829. "title": "Prototype Pollution in lodash",
  830. "url": "https://github.com/advisories/GHSA-jf85-cpcp-j695",
  831. "severity": "critical",
  832. "cwe": [
  833. "CWE-20",
  834. "CWE-1321"
  835. ],
  836. "cvss": {
  837. "score": 9.1,
  838. "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H"
  839. },
  840. "range": "\u003c4.17.12"
  841. },
  842. {
  843. "source": 1106920,
  844. "name": "lodash",
  845. "dependency": "lodash",
  846. "title": "Prototype Pollution in lodash",
  847. "url": "https://github.com/advisories/GHSA-p6mc-m468-83gw",
  848. "severity": "high",
  849. "cwe": [
  850. "CWE-770",
  851. "CWE-1321"
  852. ],
  853. "cvss": {
  854. "score": 7.4,
  855. "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H"
  856. },
  857. "range": "\u003e=3.7.0 \u003c4.17.19"
  858. },
  859. {
  860. "source": 1108258,
  861. "name": "lodash",
  862. "dependency": "lodash",
  863. "title": "Regular Expression Denial of Service (ReDoS) in lodash",
  864. "url": "https://github.com/advisories/GHSA-29mw-wpgm-hmr9",
  865. "severity": "moderate",
  866. "cwe": [
  867. "CWE-400",
  868. "CWE-1333"
  869. ],
  870. "cvss": {
  871. "score": 5.3,
  872. "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
  873. },
  874. "range": "\u003e=4.0.0 \u003c4.17.21"
  875. }
  876. ],
  877. "effects": [
  878. "microcli"
  879. ],
  880. "range": "\u003c=4.17.20",
  881. "nodes": [
  882. "node_modules/microcli/node_modules/lodash"
  883. ],
  884. "fixAvailable": {
  885. "name": "runjs",
  886. "version": "4.1.3",
  887. "isSemVerMajor": true
  888. }
  889. },
  890. "microcli": {
  891. "name": "microcli",
  892. "severity": "high",
  893. "isDirect": false,
  894. "via": [
  895. "lodash"
  896. ],
  897. "effects": [
  898. "runjs"
  899. ],
  900. "range": "\u003e=1.1.0",
  901. "nodes": [
  902. "node_modules/microcli"
  903. ],
  904. "fixAvailable": {
  905. "name": "runjs",
  906. "version": "4.1.3",
  907. "isSemVerMajor": true
  908. }
  909. },
  910. "multicast-dns": {
  911. "name": "multicast-dns",
  912. "severity": "high",
  913. "isDirect": false,
  914. "via": [
  915. "dns-packet"
  916. ],
  917. "effects": [
  918. "bonjour"
  919. ],
  920. "range": "6.0.0 - 7.2.2",
  921. "nodes": [
  922. "node_modules/multicast-dns"
  923. ],
  924. "fixAvailable": true
  925. },
  926. "postcss": {
  927. "name": "postcss",
  928. "severity": "moderate",
  929. "isDirect": false,
  930. "via": [
  931. {
  932. "source": 1093539,
  933. "name": "postcss",
  934. "dependency": "postcss",
  935. "title": "Regular Expression Denial of Service in postcss",
  936. "url": "https://github.com/advisories/GHSA-566m-qj78-rww5",
  937. "severity": "moderate",
  938. "cwe": [
  939. "CWE-400"
  940. ],
  941. "cvss": {
  942. "score": 5.3,
  943. "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"
  944. },
  945. "range": "\u003c7.0.36"
  946. },
  947. {
  948. "source": 1109574,
  949. "name": "postcss",
  950. "dependency": "postcss",
  951. "title": "PostCSS line return parsing error",
  952. "url": "https://github.com/advisories/GHSA-7fh5-64p2-3v2j",
  953. "severity": "moderate",
  954. "cwe": [
  955. "CWE-74",
  956. "CWE-144"
  957. ],
  958. "cvss": {
  959. "score": 5.3,
  960. "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"
  961. },
  962. "range": "\u003c8.4.31"
  963. }
  964. ],
  965. "effects": [
  966. "@intervolga/optimize-cssnano-plugin",
  967. "@vue/component-compiler-utils",
  968. "autoprefixer",
  969. "css-declaration-sorter",
  970. "css-loader",
  971. "cssnano",
  972. "cssnano-preset-default",
  973. "cssnano-util-raw-cache",
  974. "icss-utils",
  975. "postcss-calc",
  976. "postcss-colormin",
  977. "postcss-convert-values",
  978. "postcss-discard-comments",
  979. "postcss-discard-duplicates",
  980. "postcss-discard-empty",
  981. "postcss-discard-overridden",
  982. "postcss-loader",
  983. "postcss-merge-longhand",
  984. "postcss-merge-rules",
  985. "postcss-minify-font-values",
  986. "postcss-minify-gradients",
  987. "postcss-minify-params",
  988. "postcss-minify-selectors",
  989. "postcss-modules-extract-imports",
  990. "postcss-modules-local-by-default",
  991. "postcss-modules-scope",
  992. "postcss-modules-values",
  993. "postcss-normalize-charset",
  994. "postcss-normalize-display-values",
  995. "postcss-normalize-positions",
  996. "postcss-normalize-repeat-style",
  997. "postcss-normalize-string",
  998. "postcss-normalize-timing-functions",
  999. "postcss-normalize-unicode",
  1000. "postcss-normalize-url",
  1001. "postcss-normalize-whitespace",
  1002. "postcss-ordered-values",
  1003. "postcss-reduce-initial",
  1004. "postcss-reduce-transforms",
  1005. "postcss-svgo",
  1006. "postcss-unique-selectors",
  1007. "stylehacks",
  1008. "svg-baker"
  1009. ],
  1010. "range": "\u003c=8.4.30",
  1011. "nodes": [
  1012. "node_modules/postcss",
  1013. "node_modules/svg-baker/node_modules/postcss"
  1014. ],
  1015. "fixAvailable": {
  1016. "name": "@vue/cli-plugin-babel",
  1017. "version": "5.0.9",
  1018. "isSemVerMajor": true
  1019. }
  1020. },
  1021. "postcss-calc": {
  1022. "name": "postcss-calc",
  1023. "severity": "moderate",
  1024. "isDirect": false,
  1025. "via": [
  1026. "postcss"
  1027. ],
  1028. "effects": [
  1029. ],
  1030. "range": "4.1.0 - 7.0.5",
  1031. "nodes": [
  1032. "node_modules/postcss-calc"
  1033. ],
  1034. "fixAvailable": true
  1035. },
  1036. "postcss-colormin": {
  1037. "name": "postcss-colormin",
  1038. "severity": "moderate",
  1039. "isDirect": false,
  1040. "via": [
  1041. "postcss"
  1042. ],
  1043. "effects": [
  1044. ],
  1045. "range": "\u003c=4.0.3",
  1046. "nodes": [
  1047. "node_modules/postcss-colormin"
  1048. ],
  1049. "fixAvailable": true
  1050. },
  1051. "postcss-convert-values": {
  1052. "name": "postcss-convert-values",
  1053. "severity": "moderate",
  1054. "isDirect": false,
  1055. "via": [
  1056. "postcss"
  1057. ],
  1058. "effects": [
  1059. ],
  1060. "range": "\u003c=4.0.1",
  1061. "nodes": [
  1062. "node_modules/postcss-convert-values"
  1063. ],
  1064. "fixAvailable": true
  1065. },
  1066. "postcss-discard-comments": {
  1067. "name": "postcss-discard-comments",
  1068. "severity": "moderate",
  1069. "isDirect": false,
  1070. "via": [
  1071. "postcss"
  1072. ],
  1073. "effects": [
  1074. ],
  1075. "range": "\u003c=4.0.2",
  1076. "nodes": [
  1077. "node_modules/postcss-discard-comments"
  1078. ],
  1079. "fixAvailable": true
  1080. },
  1081. "postcss-discard-duplicates": {
  1082. "name": "postcss-discard-duplicates",
  1083. "severity": "moderate",
  1084. "isDirect": false,
  1085. "via": [
  1086. "postcss"
  1087. ],
  1088. "effects": [
  1089. ],
  1090. "range": "1.1.0 - 4.0.2",
  1091. "nodes": [
  1092. "node_modules/postcss-discard-duplicates"
  1093. ],
  1094. "fixAvailable": true
  1095. },
  1096. "postcss-discard-empty": {
  1097. "name": "postcss-discard-empty",
  1098. "severity": "moderate",
  1099. "isDirect": false,
  1100. "via": [
  1101. "postcss"
  1102. ],
  1103. "effects": [
  1104. ],
  1105. "range": "1.1.0 - 4.0.1",
  1106. "nodes": [
  1107. "node_modules/postcss-discard-empty"
  1108. ],
  1109. "fixAvailable": true
  1110. },
  1111. "postcss-discard-overridden": {
  1112. "name": "postcss-discard-overridden",
  1113. "severity": "moderate",
  1114. "isDirect": false,
  1115. "via": [
  1116. "postcss"
  1117. ],
  1118. "effects": [
  1119. ],
  1120. "range": "\u003c=4.0.1",
  1121. "nodes": [
  1122. "node_modules/postcss-discard-overridden"
  1123. ],
  1124. "fixAvailable": true
  1125. },
  1126. "postcss-loader": {
  1127. "name": "postcss-loader",
  1128. "severity": "moderate",
  1129. "isDirect": false,
  1130. "via": [
  1131. "postcss"
  1132. ],
  1133. "effects": [
  1134. ],
  1135. "range": "\u003c=4.0.1",
  1136. "nodes": [
  1137. "node_modules/postcss-loader"
  1138. ],
  1139. "fixAvailable": true
  1140. },
  1141. "postcss-merge-longhand": {
  1142. "name": "postcss-merge-longhand",
  1143. "severity": "moderate",
  1144. "isDirect": false,
  1145. "via": [
  1146. "postcss",
  1147. "stylehacks"
  1148. ],
  1149. "effects": [
  1150. ],
  1151. "range": "\u003c=4.0.11",
  1152. "nodes": [
  1153. "node_modules/postcss-merge-longhand"
  1154. ],
  1155. "fixAvailable": true
  1156. },
  1157. "postcss-merge-rules": {
  1158. "name": "postcss-merge-rules",
  1159. "severity": "moderate",
  1160. "isDirect": false,
  1161. "via": [
  1162. "postcss"
  1163. ],
  1164. "effects": [
  1165. ],
  1166. "range": "\u003c=4.0.3",
  1167. "nodes": [
  1168. "node_modules/postcss-merge-rules"
  1169. ],
  1170. "fixAvailable": true
  1171. },
  1172. "postcss-minify-font-values": {
  1173. "name": "postcss-minify-font-values",
  1174. "severity": "moderate",
  1175. "isDirect": false,
  1176. "via": [
  1177. "postcss"
  1178. ],
  1179. "effects": [
  1180. ],
  1181. "range": "\u003c=4.0.2",
  1182. "nodes": [
  1183. "node_modules/postcss-minify-font-values"
  1184. ],
  1185. "fixAvailable": true
  1186. },
  1187. "postcss-minify-gradients": {
  1188. "name": "postcss-minify-gradients",
  1189. "severity": "moderate",
  1190. "isDirect": false,
  1191. "via": [
  1192. "postcss"
  1193. ],
  1194. "effects": [
  1195. ],
  1196. "range": "\u003c=4.0.2",
  1197. "nodes": [
  1198. "node_modules/postcss-minify-gradients"
  1199. ],
  1200. "fixAvailable": true
  1201. },
  1202. "postcss-minify-params": {
  1203. "name": "postcss-minify-params",
  1204. "severity": "moderate",
  1205. "isDirect": false,
  1206. "via": [
  1207. "postcss"
  1208. ],
  1209. "effects": [
  1210. ],
  1211. "range": "\u003c=4.0.2",
  1212. "nodes": [
  1213. "node_modules/postcss-minify-params"
  1214. ],
  1215. "fixAvailable": true
  1216. },
  1217. "postcss-minify-selectors": {
  1218. "name": "postcss-minify-selectors",
  1219. "severity": "moderate",
  1220. "isDirect": false,
  1221. "via": [
  1222. "postcss"
  1223. ],
  1224. "effects": [
  1225. ],
  1226. "range": "\u003c=4.0.2",
  1227. "nodes": [
  1228. "node_modules/postcss-minify-selectors"
  1229. ],
  1230. "fixAvailable": true
  1231. },
  1232. "postcss-modules-extract-imports": {
  1233. "name": "postcss-modules-extract-imports",
  1234. "severity": "moderate",
  1235. "isDirect": false,
  1236. "via": [
  1237. "postcss"
  1238. ],
  1239. "effects": [
  1240. ],
  1241. "range": "\u003c=2.0.0",
  1242. "nodes": [
  1243. "node_modules/postcss-modules-extract-imports"
  1244. ],
  1245. "fixAvailable": true
  1246. },
  1247. "postcss-modules-local-by-default": {
  1248. "name": "postcss-modules-local-by-default",
  1249. "severity": "moderate",
  1250. "isDirect": false,
  1251. "via": [
  1252. "icss-utils",
  1253. "postcss"
  1254. ],
  1255. "effects": [
  1256. ],
  1257. "range": "\u003c=4.0.0-rc.4",
  1258. "nodes": [
  1259. "node_modules/postcss-modules-local-by-default"
  1260. ],
  1261. "fixAvailable": true
  1262. },
  1263. "postcss-modules-scope": {
  1264. "name": "postcss-modules-scope",
  1265. "severity": "moderate",
  1266. "isDirect": false,
  1267. "via": [
  1268. "postcss"
  1269. ],
  1270. "effects": [
  1271. ],
  1272. "range": "\u003c=2.2.0",
  1273. "nodes": [
  1274. "node_modules/postcss-modules-scope"
  1275. ],
  1276. "fixAvailable": true
  1277. },
  1278. "postcss-modules-values": {
  1279. "name": "postcss-modules-values",
  1280. "severity": "moderate",
  1281. "isDirect": false,
  1282. "via": [
  1283. "icss-utils",
  1284. "postcss"
  1285. ],
  1286. "effects": [
  1287. "css-loader"
  1288. ],
  1289. "range": "\u003c=4.0.0-rc.5",
  1290. "nodes": [
  1291. "node_modules/postcss-modules-values"
  1292. ],
  1293. "fixAvailable": {
  1294. "name": "@vue/cli-plugin-babel",
  1295. "version": "5.0.9",
  1296. "isSemVerMajor": true
  1297. }
  1298. },
  1299. "postcss-normalize-charset": {
  1300. "name": "postcss-normalize-charset",
  1301. "severity": "moderate",
  1302. "isDirect": false,
  1303. "via": [
  1304. "postcss"
  1305. ],
  1306. "effects": [
  1307. ],
  1308. "range": "\u003c=4.0.1",
  1309. "nodes": [
  1310. "node_modules/postcss-normalize-charset"
  1311. ],
  1312. "fixAvailable": true
  1313. },
  1314. "postcss-normalize-display-values": {
  1315. "name": "postcss-normalize-display-values",
  1316. "severity": "moderate",
  1317. "isDirect": false,
  1318. "via": [
  1319. "postcss"
  1320. ],
  1321. "effects": [
  1322. ],
  1323. "range": "\u003c=4.0.2",
  1324. "nodes": [
  1325. "node_modules/postcss-normalize-display-values"
  1326. ],
  1327. "fixAvailable": true
  1328. },
  1329. "postcss-normalize-positions": {
  1330. "name": "postcss-normalize-positions",
  1331. "severity": "moderate",
  1332. "isDirect": false,
  1333. "via": [
  1334. "postcss"
  1335. ],
  1336. "effects": [
  1337. ],
  1338. "range": "\u003c=4.0.2",
  1339. "nodes": [
  1340. "node_modules/postcss-normalize-positions"
  1341. ],
  1342. "fixAvailable": true
  1343. },
  1344. "postcss-normalize-repeat-style": {
  1345. "name": "postcss-normalize-repeat-style",
  1346. "severity": "moderate",
  1347. "isDirect": false,
  1348. "via": [
  1349. "postcss"
  1350. ],
  1351. "effects": [
  1352. ],
  1353. "range": "\u003c=4.0.2",
  1354. "nodes": [
  1355. "node_modules/postcss-normalize-repeat-style"
  1356. ],
  1357. "fixAvailable": true
  1358. },
  1359. "postcss-normalize-string": {
  1360. "name": "postcss-normalize-string",
  1361. "severity": "moderate",
  1362. "isDirect": false,
  1363. "via": [
  1364. "postcss"
  1365. ],
  1366. "effects": [
  1367. ],
  1368. "range": "\u003c=4.0.2",
  1369. "nodes": [
  1370. "node_modules/postcss-normalize-string"
  1371. ],
  1372. "fixAvailable": true
  1373. },
  1374. "postcss-normalize-timing-functions": {
  1375. "name": "postcss-normalize-timing-functions",
  1376. "severity": "moderate",
  1377. "isDirect": false,
  1378. "via": [
  1379. "postcss"
  1380. ],
  1381. "effects": [
  1382. ],
  1383. "range": "\u003c=4.0.2",
  1384. "nodes": [
  1385. "node_modules/postcss-normalize-timing-functions"
  1386. ],
  1387. "fixAvailable": true
  1388. },
  1389. "postcss-normalize-unicode": {
  1390. "name": "postcss-normalize-unicode",
  1391. "severity": "moderate",
  1392. "isDirect": false,
  1393. "via": [
  1394. "postcss"
  1395. ],
  1396. "effects": [
  1397. ],
  1398. "range": "\u003c=4.0.1",
  1399. "nodes": [
  1400. "node_modules/postcss-normalize-unicode"
  1401. ],
  1402. "fixAvailable": true
  1403. },
  1404. "postcss-normalize-url": {
  1405. "name": "postcss-normalize-url",
  1406. "severity": "moderate",
  1407. "isDirect": false,
  1408. "via": [
  1409. "postcss"
  1410. ],
  1411. "effects": [
  1412. ],
  1413. "range": "1.1.0 - 4.0.1",
  1414. "nodes": [
  1415. "node_modules/postcss-normalize-url"
  1416. ],
  1417. "fixAvailable": true
  1418. },
  1419. "postcss-normalize-whitespace": {
  1420. "name": "postcss-normalize-whitespace",
  1421. "severity": "moderate",
  1422. "isDirect": false,
  1423. "via": [
  1424. "postcss"
  1425. ],
  1426. "effects": [
  1427. ],
  1428. "range": "\u003c=4.0.2",
  1429. "nodes": [
  1430. "node_modules/postcss-normalize-whitespace"
  1431. ],
  1432. "fixAvailable": true
  1433. },
  1434. "postcss-ordered-values": {
  1435. "name": "postcss-ordered-values",
  1436. "severity": "moderate",
  1437. "isDirect": false,
  1438. "via": [
  1439. "postcss"
  1440. ],
  1441. "effects": [
  1442. ],
  1443. "range": "\u003c=4.1.2",
  1444. "nodes": [
  1445. "node_modules/postcss-ordered-values"
  1446. ],
  1447. "fixAvailable": true
  1448. },
  1449. "postcss-reduce-initial": {
  1450. "name": "postcss-reduce-initial",
  1451. "severity": "moderate",
  1452. "isDirect": false,
  1453. "via": [
  1454. "postcss"
  1455. ],
  1456. "effects": [
  1457. ],
  1458. "range": "\u003c=4.0.3",
  1459. "nodes": [
  1460. "node_modules/postcss-reduce-initial"
  1461. ],
  1462. "fixAvailable": true
  1463. },
  1464. "postcss-reduce-transforms": {
  1465. "name": "postcss-reduce-transforms",
  1466. "severity": "moderate",
  1467. "isDirect": false,
  1468. "via": [
  1469. "postcss"
  1470. ],
  1471. "effects": [
  1472. ],
  1473. "range": "\u003c=4.0.2",
  1474. "nodes": [
  1475. "node_modules/postcss-reduce-transforms"
  1476. ],
  1477. "fixAvailable": true
  1478. },
  1479. "postcss-svgo": {
  1480. "name": "postcss-svgo",
  1481. "severity": "moderate",
  1482. "isDirect": false,
  1483. "via": [
  1484. "postcss"
  1485. ],
  1486. "effects": [
  1487. ],
  1488. "range": "\u003c=4.0.3",
  1489. "nodes": [
  1490. "node_modules/postcss-svgo"
  1491. ],
  1492. "fixAvailable": true
  1493. },
  1494. "postcss-unique-selectors": {
  1495. "name": "postcss-unique-selectors",
  1496. "severity": "moderate",
  1497. "isDirect": false,
  1498. "via": [
  1499. "postcss"
  1500. ],
  1501. "effects": [
  1502. ],
  1503. "range": "\u003c=4.0.1",
  1504. "nodes": [
  1505. "node_modules/postcss-unique-selectors"
  1506. ],
  1507. "fixAvailable": true
  1508. },
  1509. "request": {
  1510. "name": "request",
  1511. "severity": "critical",
  1512. "isDirect": false,
  1513. "via": [
  1514. {
  1515. "source": 1096727,
  1516. "name": "request",
  1517. "dependency": "request",
  1518. "title": "Server-Side Request Forgery in Request",
  1519. "url": "https://github.com/advisories/GHSA-p8p7-x288-28g6",
  1520. "severity": "moderate",
  1521. "cwe": [
  1522. "CWE-918"
  1523. ],
  1524. "cvss": {
  1525. "score": 6.1,
  1526. "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"
  1527. },
  1528. "range": "\u003c=2.88.2"
  1529. },
  1530. "form-data",
  1531. "tough-cookie"
  1532. ],
  1533. "effects": [
  1534. "@vue/cli-shared-utils"
  1535. ],
  1536. "range": "*",
  1537. "nodes": [
  1538. "node_modules/request"
  1539. ],
  1540. "fixAvailable": {
  1541. "name": "@vue/cli-plugin-eslint",
  1542. "version": "5.0.9",
  1543. "isSemVerMajor": true
  1544. }
  1545. },
  1546. "runjs": {
  1547. "name": "runjs",
  1548. "severity": "high",
  1549. "isDirect": true,
  1550. "via": [
  1551. "microcli"
  1552. ],
  1553. "effects": [
  1554. ],
  1555. "range": "\u003e=4.2.0",
  1556. "nodes": [
  1557. "node_modules/runjs"
  1558. ],
  1559. "fixAvailable": {
  1560. "name": "runjs",
  1561. "version": "4.1.3",
  1562. "isSemVerMajor": true
  1563. }
  1564. },
  1565. "stylehacks": {
  1566. "name": "stylehacks",
  1567. "severity": "moderate",
  1568. "isDirect": false,
  1569. "via": [
  1570. "postcss"
  1571. ],
  1572. "effects": [
  1573. "postcss-merge-longhand"
  1574. ],
  1575. "range": "\u003c=4.0.3",
  1576. "nodes": [
  1577. "node_modules/stylehacks"
  1578. ],
  1579. "fixAvailable": true
  1580. },
  1581. "svg-baker": {
  1582. "name": "svg-baker",
  1583. "severity": "moderate",
  1584. "isDirect": false,
  1585. "via": [
  1586. "postcss"
  1587. ],
  1588. "effects": [
  1589. "svg-baker-runtime",
  1590. "svg-sprite-loader"
  1591. ],
  1592. "range": "\u003e=1.2.5",
  1593. "nodes": [
  1594. "node_modules/svg-baker"
  1595. ],
  1596. "fixAvailable": {
  1597. "name": "svg-sprite-loader",
  1598. "version": "5.2.1",
  1599. "isSemVerMajor": false
  1600. }
  1601. },
  1602. "svg-baker-runtime": {
  1603. "name": "svg-baker-runtime",
  1604. "severity": "moderate",
  1605. "isDirect": false,
  1606. "via": [
  1607. "svg-baker"
  1608. ],
  1609. "effects": [
  1610. "svg-sprite-loader"
  1611. ],
  1612. "range": "\u003e=1.4.0-alpha.10475b37",
  1613. "nodes": [
  1614. "node_modules/svg-baker-runtime"
  1615. ],
  1616. "fixAvailable": {
  1617. "name": "svg-sprite-loader",
  1618. "version": "5.2.1",
  1619. "isSemVerMajor": false
  1620. }
  1621. },
  1622. "svg-sprite-loader": {
  1623. "name": "svg-sprite-loader",
  1624. "severity": "critical",
  1625. "isDirect": true,
  1626. "via": [
  1627. "html-webpack-plugin",
  1628. "svg-baker",
  1629. "svg-baker-runtime"
  1630. ],
  1631. "effects": [
  1632. ],
  1633. "range": "\u003e=2.0.4",
  1634. "nodes": [
  1635. "node_modules/svg-sprite-loader"
  1636. ],
  1637. "fixAvailable": {
  1638. "name": "svg-sprite-loader",
  1639. "version": "5.2.1",
  1640. "isSemVerMajor": false
  1641. }
  1642. },
  1643. "tmp": {
  1644. "name": "tmp",
  1645. "severity": "low",
  1646. "isDirect": false,
  1647. "via": [
  1648. {
  1649. "source": 1109537,
  1650. "name": "tmp",
  1651. "dependency": "tmp",
  1652. "title": "tmp allows arbitrary temporary file / directory write via symbolic link `dir` parameter",
  1653. "url": "https://github.com/advisories/GHSA-52f5-9888-hmc6",
  1654. "severity": "low",
  1655. "cwe": [
  1656. "CWE-59"
  1657. ],
  1658. "cvss": {
  1659. "score": 2.5,
  1660. "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N"
  1661. },
  1662. "range": "\u003c=0.2.3"
  1663. }
  1664. ],
  1665. "effects": [
  1666. "external-editor"
  1667. ],
  1668. "range": "\u003c=0.2.3",
  1669. "nodes": [
  1670. "node_modules/tmp"
  1671. ],
  1672. "fixAvailable": {
  1673. "name": "@vue/cli-plugin-eslint",
  1674. "version": "5.0.9",
  1675. "isSemVerMajor": true
  1676. }
  1677. },
  1678. "tough-cookie": {
  1679. "name": "tough-cookie",
  1680. "severity": "moderate",
  1681. "isDirect": false,
  1682. "via": [
  1683. {
  1684. "source": 1097682,
  1685. "name": "tough-cookie",
  1686. "dependency": "tough-cookie",
  1687. "title": "tough-cookie Prototype Pollution vulnerability",
  1688. "url": "https://github.com/advisories/GHSA-72xf-g2v4-qvf3",
  1689. "severity": "moderate",
  1690. "cwe": [
  1691. "CWE-1321"
  1692. ],
  1693. "cvss": {
  1694. "score": 6.5,
  1695. "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N"
  1696. },
  1697. "range": "\u003c4.1.3"
  1698. }
  1699. ],
  1700. "effects": [
  1701. "request"
  1702. ],
  1703. "range": "\u003c4.1.3",
  1704. "nodes": [
  1705. "node_modules/tough-cookie"
  1706. ],
  1707. "fixAvailable": {
  1708. "name": "@vue/cli-plugin-eslint",
  1709. "version": "5.0.9",
  1710. "isSemVerMajor": true
  1711. }
  1712. },
  1713. "vue": {
  1714. "name": "vue",
  1715. "severity": "low",
  1716. "isDirect": true,
  1717. "via": [
  1718. {
  1719. "source": 1100238,
  1720. "name": "vue",
  1721. "dependency": "vue",
  1722. "title": "ReDoS vulnerability in vue package that is exploitable through inefficient regex evaluation in the parseHTML function",
  1723. "url": "https://github.com/advisories/GHSA-5j4c-8p2g-v4jx",
  1724. "severity": "low",
  1725. "cwe": [
  1726. "CWE-1333"
  1727. ],
  1728. "cvss": {
  1729. "score": 3.7,
  1730. "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"
  1731. },
  1732. "range": "\u003e=2.0.0-alpha.1 \u003c3.0.0-alpha.0"
  1733. }
  1734. ],
  1735. "effects": [
  1736. "@riophae/vue-treeselect",
  1737. "element-ui",
  1738. "vuex"
  1739. ],
  1740. "range": "2.0.0-alpha.1 - 2.7.16",
  1741. "nodes": [
  1742. "node_modules/vue"
  1743. ],
  1744. "fixAvailable": {
  1745. "name": "element-ui",
  1746. "version": "0.2.6",
  1747. "isSemVerMajor": true
  1748. }
  1749. },
  1750. "vue-loader": {
  1751. "name": "vue-loader",
  1752. "severity": "moderate",
  1753. "isDirect": false,
  1754. "via": [
  1755. "@vue/component-compiler-utils"
  1756. ],
  1757. "effects": [
  1758. ],
  1759. "range": "15.0.0-beta.1 - 15.11.1",
  1760. "nodes": [
  1761. "node_modules/vue-loader"
  1762. ],
  1763. "fixAvailable": true
  1764. },
  1765. "vue-template-compiler": {
  1766. "name": "vue-template-compiler",
  1767. "severity": "moderate",
  1768. "isDirect": true,
  1769. "via": [
  1770. {
  1771. "source": 1098721,
  1772. "name": "vue-template-compiler",
  1773. "dependency": "vue-template-compiler",
  1774. "title": "vue-template-compiler vulnerable to client-side Cross-Site Scripting (XSS)",
  1775. "url": "https://github.com/advisories/GHSA-g3ch-rx76-35fx",
  1776. "severity": "moderate",
  1777. "cwe": [
  1778. "CWE-79"
  1779. ],
  1780. "cvss": {
  1781. "score": 4.2,
  1782. "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N"
  1783. },
  1784. "range": "\u003e=2.0.0 \u003c3.0.0"
  1785. }
  1786. ],
  1787. "effects": [
  1788. "@vue/cli-service"
  1789. ],
  1790. "range": "\u003e=2.0.0",
  1791. "nodes": [
  1792. "node_modules/vue-template-compiler"
  1793. ],
  1794. "fixAvailable": {
  1795. "name": "@vue/cli-plugin-babel",
  1796. "version": "5.0.9",
  1797. "isSemVerMajor": true
  1798. }
  1799. },
  1800. "vuex": {
  1801. "name": "vuex",
  1802. "severity": "low",
  1803. "isDirect": true,
  1804. "via": [
  1805. "vue"
  1806. ],
  1807. "effects": [
  1808. ],
  1809. "range": "3.1.3 - 3.6.2",
  1810. "nodes": [
  1811. "node_modules/vuex"
  1812. ],
  1813. "fixAvailable": {
  1814. "name": "vuex",
  1815. "version": "4.1.0",
  1816. "isSemVerMajor": true
  1817. }
  1818. },
  1819. "webpack-dev-server": {
  1820. "name": "webpack-dev-server",
  1821. "severity": "high",
  1822. "isDirect": false,
  1823. "via": [
  1824. {
  1825. "source": 1108429,
  1826. "name": "webpack-dev-server",
  1827. "dependency": "webpack-dev-server",
  1828. "title": "webpack-dev-server users\u0027 source code may be stolen when they access a malicious web site with non-Chromium based browser",
  1829. "url": "https://github.com/advisories/GHSA-9jgg-88mc-972h",
  1830. "severity": "moderate",
  1831. "cwe": [
  1832. "CWE-346"
  1833. ],
  1834. "cvss": {
  1835. "score": 6.5,
  1836. "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"
  1837. },
  1838. "range": "\u003c=5.2.0"
  1839. },
  1840. {
  1841. "source": 1108430,
  1842. "name": "webpack-dev-server",
  1843. "dependency": "webpack-dev-server",
  1844. "title": "webpack-dev-server users\u0027 source code may be stolen when they access a malicious web site",
  1845. "url": "https://github.com/advisories/GHSA-4v9v-hfq4-rm2v",
  1846. "severity": "moderate",
  1847. "cwe": [
  1848. "CWE-749"
  1849. ],
  1850. "cvss": {
  1851. "score": 5.3,
  1852. "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N"
  1853. },
  1854. "range": "\u003c=5.2.0"
  1855. },
  1856. "bonjour",
  1857. "http-proxy-middleware",
  1858. "ip"
  1859. ],
  1860. "effects": [
  1861. ],
  1862. "range": "\u003c=5.2.0",
  1863. "nodes": [
  1864. "node_modules/webpack-dev-server"
  1865. ],
  1866. "fixAvailable": true
  1867. },
  1868. "yorkie": {
  1869. "name": "yorkie",
  1870. "severity": "high",
  1871. "isDirect": false,
  1872. "via": [
  1873. "execa"
  1874. ],
  1875. "effects": [
  1876. "@vue/cli-plugin-eslint"
  1877. ],
  1878. "range": "*",
  1879. "nodes": [
  1880. "node_modules/yorkie"
  1881. ],
  1882. "fixAvailable": {
  1883. "name": "@vue/cli-plugin-eslint",
  1884. "version": "5.0.9",
  1885. "isSemVerMajor": true
  1886. }
  1887. }
  1888. }