mirror of
https://github.com/diegosouzapw/OmniRoute.git
synced 2026-07-31 04:12:10 +03:00
Update the direct Next.js dependency to a patched release in response to the reported audit findings. Switch the provider diversity test to Vitest's expect API for consistent test runner usage and add the audit report snapshot for release verification.
204 lines
6.1 KiB
JSON
204 lines
6.1 KiB
JSON
{
|
|
"auditReportVersion": 2,
|
|
"vulnerabilities": {
|
|
"next": {
|
|
"name": "next",
|
|
"severity": "high",
|
|
"isDirect": true,
|
|
"via": [
|
|
{
|
|
"source": 1112592,
|
|
"name": "next",
|
|
"dependency": "next",
|
|
"title": "Next.js self-hosted applications vulnerable to DoS via Image Optimizer remotePatterns configuration",
|
|
"url": "https://github.com/advisories/GHSA-9g9p-9gw9-jx7f",
|
|
"severity": "moderate",
|
|
"cwe": ["CWE-400", "CWE-770"],
|
|
"cvss": {
|
|
"score": 5.9,
|
|
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
|
|
},
|
|
"range": ">=15.6.0-canary.0 <16.1.5"
|
|
},
|
|
{
|
|
"source": 1112646,
|
|
"name": "next",
|
|
"dependency": "next",
|
|
"title": "Next.js HTTP request deserialization can lead to DoS when using insecure React Server Components",
|
|
"url": "https://github.com/advisories/GHSA-h25m-26qc-wcjf",
|
|
"severity": "high",
|
|
"cwe": ["CWE-400", "CWE-502"],
|
|
"cvss": {
|
|
"score": 7.5,
|
|
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"
|
|
},
|
|
"range": ">=16.0.0-beta.0 <16.0.11"
|
|
},
|
|
{
|
|
"source": 1112990,
|
|
"name": "next",
|
|
"dependency": "next",
|
|
"title": "Next.js has Unbounded Memory Consumption via PPR Resume Endpoint ",
|
|
"url": "https://github.com/advisories/GHSA-5f7q-jpqc-wp7h",
|
|
"severity": "moderate",
|
|
"cwe": ["CWE-400", "CWE-409", "CWE-770"],
|
|
"cvss": {
|
|
"score": 5.9,
|
|
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
|
|
},
|
|
"range": ">=16.0.0-beta.0 <16.1.5"
|
|
},
|
|
{
|
|
"source": 1114898,
|
|
"name": "next",
|
|
"dependency": "next",
|
|
"title": "Next.js: HTTP request smuggling in rewrites",
|
|
"url": "https://github.com/advisories/GHSA-ggv3-7p47-pfv8",
|
|
"severity": "moderate",
|
|
"cwe": ["CWE-444"],
|
|
"cvss": {
|
|
"score": 0,
|
|
"vectorString": null
|
|
},
|
|
"range": ">=16.0.0-beta.0 <16.1.7"
|
|
},
|
|
{
|
|
"source": 1114941,
|
|
"name": "next",
|
|
"dependency": "next",
|
|
"title": "Next.js: Unbounded next/image disk cache growth can exhaust storage",
|
|
"url": "https://github.com/advisories/GHSA-3x4c-7xq6-9pq8",
|
|
"severity": "moderate",
|
|
"cwe": ["CWE-400"],
|
|
"cvss": {
|
|
"score": 0,
|
|
"vectorString": null
|
|
},
|
|
"range": ">=16.0.0-beta.0 <16.1.7"
|
|
},
|
|
{
|
|
"source": 1114942,
|
|
"name": "next",
|
|
"dependency": "next",
|
|
"title": "Next.js: Unbounded postponed resume buffering can lead to DoS",
|
|
"url": "https://github.com/advisories/GHSA-h27x-g6w4-24gq",
|
|
"severity": "moderate",
|
|
"cwe": ["CWE-770"],
|
|
"cvss": {
|
|
"score": 0,
|
|
"vectorString": null
|
|
},
|
|
"range": ">=16.0.1 <16.1.7"
|
|
},
|
|
{
|
|
"source": 1114943,
|
|
"name": "next",
|
|
"dependency": "next",
|
|
"title": "Next.js: null origin can bypass Server Actions CSRF checks",
|
|
"url": "https://github.com/advisories/GHSA-mq59-m269-xvcx",
|
|
"severity": "moderate",
|
|
"cwe": ["CWE-352"],
|
|
"cvss": {
|
|
"score": 0,
|
|
"vectorString": null
|
|
},
|
|
"range": ">=16.0.1 <16.1.7"
|
|
},
|
|
{
|
|
"source": 1115360,
|
|
"name": "next",
|
|
"dependency": "next",
|
|
"title": "Next.js: null origin can bypass dev HMR websocket CSRF checks",
|
|
"url": "https://github.com/advisories/GHSA-jcc7-9wpm-mj36",
|
|
"severity": "low",
|
|
"cwe": ["CWE-1385"],
|
|
"cvss": {
|
|
"score": 0,
|
|
"vectorString": null
|
|
},
|
|
"range": ">=16.0.1 <16.1.7"
|
|
}
|
|
],
|
|
"effects": [],
|
|
"range": "15.6.0-canary.0 - 16.1.6",
|
|
"nodes": ["node_modules/next"],
|
|
"fixAvailable": {
|
|
"name": "next",
|
|
"version": "16.2.2",
|
|
"isSemVerMajor": false
|
|
}
|
|
},
|
|
"vite": {
|
|
"name": "vite",
|
|
"severity": "high",
|
|
"isDirect": false,
|
|
"via": [
|
|
{
|
|
"source": 1116007,
|
|
"name": "vite",
|
|
"dependency": "vite",
|
|
"title": "Vite Vulnerable to Path Traversal in Optimized Deps `.map` Handling",
|
|
"url": "https://github.com/advisories/GHSA-4w7w-66w2-5vf9",
|
|
"severity": "moderate",
|
|
"cwe": ["CWE-22", "CWE-200"],
|
|
"cvss": {
|
|
"score": 0,
|
|
"vectorString": null
|
|
},
|
|
"range": ">=8.0.0 <=8.0.4"
|
|
},
|
|
{
|
|
"source": 1116009,
|
|
"name": "vite",
|
|
"dependency": "vite",
|
|
"title": "Vite: `server.fs.deny` bypassed with queries",
|
|
"url": "https://github.com/advisories/GHSA-v2wj-q39q-566r",
|
|
"severity": "high",
|
|
"cwe": ["CWE-180", "CWE-284"],
|
|
"cvss": {
|
|
"score": 0,
|
|
"vectorString": null
|
|
},
|
|
"range": ">=8.0.0 <=8.0.4"
|
|
},
|
|
{
|
|
"source": 1116012,
|
|
"name": "vite",
|
|
"dependency": "vite",
|
|
"title": "Vite Vulnerable to Arbitrary File Read via Vite Dev Server WebSocket",
|
|
"url": "https://github.com/advisories/GHSA-p9ff-h696-f583",
|
|
"severity": "high",
|
|
"cwe": ["CWE-200", "CWE-306"],
|
|
"cvss": {
|
|
"score": 0,
|
|
"vectorString": null
|
|
},
|
|
"range": ">=8.0.0 <=8.0.4"
|
|
}
|
|
],
|
|
"effects": [],
|
|
"range": "8.0.0 - 8.0.4",
|
|
"nodes": ["node_modules/vite"],
|
|
"fixAvailable": true
|
|
}
|
|
},
|
|
"metadata": {
|
|
"vulnerabilities": {
|
|
"info": 0,
|
|
"low": 0,
|
|
"moderate": 0,
|
|
"high": 2,
|
|
"critical": 0,
|
|
"total": 2
|
|
},
|
|
"dependencies": {
|
|
"prod": 407,
|
|
"dev": 485,
|
|
"optional": 154,
|
|
"peer": 480,
|
|
"peerOptional": 0,
|
|
"total": 1455
|
|
}
|
|
}
|
|
}
|