试图了解RxJ是否可以在生产中安全使用。 任何人都知道RxJS 5中的漏洞。 以下问题是否为RxJS5所知。请帮忙。
**Vulnerabilities - Public Data**
CVE-2017-1000048 High Risk Prototype Override Protection Bypass qs 2.4.2
CVE-2015-8855 High Risk Regular Expression Denial Of Service (ReDoS) semver 2.3.2
CVE-2017-1000048 High Risk Prototype Override Protection Bypass qs 5.2.1
CVE-2017-1000048 High Risk Prototype Override Protection Bypass qs 2.3.3
CVE-2017-15010 Medium Risk Regular Expression Denial Of Service (ReDoS) Via Parsing Cookies tough-cookie 2.3.2
CVE-2017-15010 Medium Risk Regular Expression Denial Of Service (ReDoS) Via Parsing Cookies tough-cookie 2.2.2
**Vulnerabilities - Premium Data**
RESERVED (CVE-2016-1000023) High Risk Regular Expression Denial Of Service (ReDoS) minimatch 0.3.0
RESERVED (CVE-2016-1000023) High Risk Regular Expression Denial Of Service (ReDoS) minimatch 2.0.10
NO-CVE High Risk Remote Code Execution (RCE) growl 1.9.2
RESERVED (CVE-2016-1000023) High Risk Regular Expression Denial Of Service (ReDoS) minimatch 2.0.4
NO-CVE Medium Risk Insecure Cipher request 2.55.0
NO-CVE Medium Risk Remote Memory Disclosure request 2.55.0
NO-CVE Medium Risk Insecure Cipher request 2.67.0
NO-CVE Medium Risk Remote Memory Disclosure request 2.67.0
RESERVED (CVE-2016-2515) Medium Risk Regular Expression Denial Of Service (ReDoS) hawk 2.3.1
NO-CVE Medium Risk Insecure Cipher request 2.79.0
NO-CVE Medium Risk Regular Expression Denial Of Service (ReDoS) debug 2.6.8
NO-CVE Medium Risk Insecure Cipher request 2.81.0
NO-CVE Medium Risk Denial Of Service (DoS) ws 1.1.5
NO-CVE Medium Risk Timing Attacks http-signature 0.10.1
NO-CVE Medium Risk Arbitrary Command Injection shelljs 0.7.6
RESERVED (CVE-2016-1000013) Medium Risk Cross-site Scripting (XSS) Due To Sanitization Bypass Using HTML Entities marked 0.3.5
NO-CVE Medium Risk Cross-site Scripting (XSS) marked 0.3.5
NO-CVE Medium Risk Cross-Site Scripting (XSS) marked 0.3.5
NO-CVE Medium Risk Regular Expression Denial Of Service (ReDoS) marked 0.3.5
NO-CVE Medium Risk Regular Expression Denial Of Service (ReDoS) debug 2.2.0
NO-CVE Medium Risk Regular Expression Denial Of Service (ReDoS) ms 0.7.3
NO-CVE Medium Risk Regular Expression Denial Of Service (ReDoS) ms 0.7.1
NO-CVE Medium Risk Regular Expression Denial Of Service (ReDoS) debug 2.6.6
NO-CVE Medium Risk Information Disclosure tunnel-agent 0.4.3
NO-CVE Medium Risk Regular Expression Denial Of Service (ReDoS) Via Long String Of Semicolons tough-cookie 2.2.2
答案 0 :(得分:0)
问题解决了。给我的报告已经恢复,说有关SourceClear如何运行的一些问题。
在RxJS中找不到漏洞。好的。
新报告回归零(0)漏洞。