NodeJS 国家预防机制审计|调试低效正则表达式复杂性漏洞-https://github.com/advisories/GHSA-9vvw-cc9w-f27h

wtlkbnrh  于 2023-01-12  发布在  Node.js
关注(0)|答案(1)|浏览(100)
# npm audit report
debug  <3.1.0
debug Inefficient Regular Expression Complexity vulnerability - https://github.com/advisories/GHSA-9vvw-cc9w-f27h
No fix available
node_modules/body-parser/node_modules/debug
node_modules/express/node_modules/debug
node_modules/finalhandler/node_modules/debug
node_modules/send/node_modules/debug
  body-parser  >=1.12.0
  Depends on vulnerable versions of debug
  node_modules/body-parser
    express  >=3.4.5
    Depends on vulnerable versions of body-parser
    Depends on vulnerable versions of debug
    Depends on vulnerable versions of finalhandler
    Depends on vulnerable versions of send
    Depends on vulnerable versions of serve-static
    node_modules/express
      inversify-express-utils  *
      Depends on vulnerable versions of express
      node_modules/inversify-express-utils
  finalhandler  *
  Depends on vulnerable versions of debug
  node_modules/finalhandler
  send  0.3.0 - 0.18.0
  Depends on vulnerable versions of debug
  node_modules/send
    serve-static  1.1.0 - 1.15.0
    Depends on vulnerable versions of send
    node_modules/serve-static
7 low severity vulnerabilities
Some issues need review, and may require choosing
a different dependency.

没有可用的修复?我能做些什么来修复这个问题。我必须降级软件包吗?这里的确切问题是什么?请有人能帮助我吗?

8mmmxcuj

8mmmxcuj1#

问题出在调试模块上,请转到您的package-lock.json和package.json并将版本更改为最新版本(4.3.4)。

相关问题