|
559 | 559 | "jquery-ui", |
560 | 560 | "jquery.ui" |
561 | 561 | ], |
| 562 | + "npmname": "jquery-ui", |
562 | 563 | "vulnerabilities": [ |
563 | 564 | { |
564 | 565 | "below": "1.13.2", |
|
671 | 672 | "jquery-ui", |
672 | 673 | "jquery.ui" |
673 | 674 | ], |
| 675 | + "npmname": "jquery-ui", |
674 | 676 | "vulnerabilities": [ |
675 | 677 | { |
676 | 678 | "atOrAbove": "1.8.9", |
|
728 | 730 | "jquery-ui", |
729 | 731 | "jquery.ui" |
730 | 732 | ], |
| 733 | + "npmname": "jquery-ui", |
731 | 734 | "vulnerabilities": [], |
732 | 735 | "extractors": { |
733 | 736 | "filecontent": [ |
|
744 | 747 | "jquery-ui", |
745 | 748 | "jquery.ui" |
746 | 749 | ], |
| 750 | + "npmname": "jquery-ui", |
747 | 751 | "vulnerabilities": [ |
748 | 752 | { |
749 | 753 | "atOrAbove": "1.9.2", |
|
779 | 783 | "bowername": [ |
780 | 784 | "jquery-prettyPhoto" |
781 | 785 | ], |
| 786 | + "basePurl": "pkg:github/scaron/prettyphoto", |
782 | 787 | "vulnerabilities": [ |
783 | 788 | { |
784 | 789 | "below": "3.1.5", |
|
826 | 831 | "bowername": [ |
827 | 832 | "jPlayer" |
828 | 833 | ], |
| 834 | + "npmname": "jplayer", |
829 | 835 | "vulnerabilities": [ |
830 | 836 | { |
831 | 837 | "below": "2.3.1", |
|
987 | 993 | "tinymce", |
988 | 994 | "tinymce-dist" |
989 | 995 | ], |
| 996 | + "npmname": "tinymce", |
990 | 997 | "vulnerabilities": [ |
991 | 998 | { |
992 | 999 | "below": "1.4.2", |
|
1196 | 1203 | "yui", |
1197 | 1204 | "yui3" |
1198 | 1205 | ], |
| 1206 | + "npmname": "yui", |
1199 | 1207 | "vulnerabilities": [ |
1200 | 1208 | { |
1201 | 1209 | "atOrAbove": "3.5.0", |
|
2307 | 2315 | "angularjs", |
2308 | 2316 | "angular.js" |
2309 | 2317 | ], |
| 2318 | + "npmname": "angular", |
2310 | 2319 | "vulnerabilities": [ |
2311 | 2320 | { |
2312 | 2321 | "below": "1.8.0", |
|
2496 | 2505 | "backbonejs", |
2497 | 2506 | "backbone" |
2498 | 2507 | ], |
| 2508 | + "npmname": "backbone", |
| 2509 | + "basePurl": "npm:npm/backbone", |
2499 | 2510 | "vulnerabilities": [ |
2500 | 2511 | { |
2501 | 2512 | "below": "0.5.0", |
|
2532 | 2543 | "mustache.js", |
2533 | 2544 | "mustache" |
2534 | 2545 | ], |
| 2546 | + "npmname": "mustache", |
| 2547 | + "basePurl": "npm:npm/mustache", |
2535 | 2548 | "vulnerabilities": [ |
2536 | 2549 | { |
2537 | 2550 | "below": "0.3.1", |
|
2925 | 2938 | } |
2926 | 2939 | }, |
2927 | 2940 | "easyXDM": { |
| 2941 | + "npmname": "easyxdm", |
2928 | 2942 | "vulnerabilities": [ |
2929 | 2943 | { |
2930 | 2944 | "below": "2.4.18", |
|
3166 | 3180 | "dompurify", |
3167 | 3181 | "DOMPurify" |
3168 | 3182 | ], |
| 3183 | + "npmname": "dompurify", |
3169 | 3184 | "vulnerabilities": [ |
3170 | 3185 | { |
3171 | 3186 | "below": "0.6.1", |
|
3514 | 3529 | } |
3515 | 3530 | }, |
3516 | 3531 | "DWR": { |
| 3532 | + "npmname": "dwr", |
3517 | 3533 | "vulnerabilities": [ |
3518 | 3534 | { |
3519 | 3535 | "below": "1.1.4", |
|
3578 | 3594 | "moment", |
3579 | 3595 | "momentjs" |
3580 | 3596 | ], |
| 3597 | + "npmname": "moment", |
| 3598 | + "basePurl": "pkg:npm/moment", |
3581 | 3599 | "vulnerabilities": [ |
3582 | 3600 | { |
3583 | 3601 | "below": "2.11.2", |
|
3664 | 3682 | "uri": [ |
3665 | 3683 | "/moment\\.js/(§§version§§)/moment(.min)?\\.js" |
3666 | 3684 | ], |
| 3685 | + "filename": [ |
| 3686 | + "moment(?:-|\\.)(§§version§§)(?:-min)?\\.js" |
| 3687 | + ], |
3667 | 3688 | "filecontent": [ |
3668 | | - "//! moment.js(?:[\n\r]+)//! version : (§§version§§)", |
| 3689 | + "//!? moment.js(?:[\n\r]+)//!? version : (§§version§§)", |
3669 | 3690 | "\\.version=\"(§§version§§)\".{300,500}\\.isMoment=" |
3670 | 3691 | ] |
3671 | 3692 | } |
|
3675 | 3696 | "Underscore", |
3676 | 3697 | "underscore" |
3677 | 3698 | ], |
| 3699 | + "npmname": "underscore", |
3678 | 3700 | "vulnerabilities": [ |
3679 | 3701 | { |
3680 | 3702 | "below": "1.12.1", |
|
4726 | 4748 | } |
4727 | 4749 | }, |
4728 | 4750 | "AlaSQL": { |
| 4751 | + "npmname": "alasql", |
4729 | 4752 | "vulnerabilities": [ |
4730 | 4753 | { |
4731 | 4754 | "below": "0.7.0", |
|
4755 | 4778 | } |
4756 | 4779 | }, |
4757 | 4780 | "jquery.datatables": { |
| 4781 | + "npmname": "datatables", |
4758 | 4782 | "vulnerabilities": [ |
4759 | 4783 | { |
4760 | 4784 | "below": "1.11.3", |
|
5009 | 5033 | ] |
5010 | 5034 | } |
5011 | 5035 | }, |
| 5036 | + "froala": { |
| 5037 | + "npmname": "froala-editor", |
| 5038 | + "vulnerabilities": [ |
| 5039 | + { |
| 5040 | + "below": "4.0.11", |
| 5041 | + "severity": "medium", |
| 5042 | + "cwe": [ |
| 5043 | + "CWE-79" |
| 5044 | + ], |
| 5045 | + "identifiers": { |
| 5046 | + "summary": "XSS vulnerability in [insert video]", |
| 5047 | + "issue": "3880" |
| 5048 | + }, |
| 5049 | + "info": [ |
| 5050 | + "https://github.com/froala/wysiwyg-editor/releases/tag/v4.0.11" |
| 5051 | + ] |
| 5052 | + }, |
| 5053 | + { |
| 5054 | + "below": "3.2.7", |
| 5055 | + "severity": "high", |
| 5056 | + "cwe": [ |
| 5057 | + "CWE-79" |
| 5058 | + ], |
| 5059 | + "identifiers": { |
| 5060 | + "summary": "Froala WYSIWYG Editor 3.2.6-1 is affected by XSS due to a namespace confusion during parsing.", |
| 5061 | + "CVE": [ |
| 5062 | + "CVE-2021-28114" |
| 5063 | + ] |
| 5064 | + }, |
| 5065 | + "info": [ |
| 5066 | + "https://bishopfox.com/blog/froala-editor-v3-2-6-advisory" |
| 5067 | + ] |
| 5068 | + }, |
| 5069 | + { |
| 5070 | + "below": "3.2.7", |
| 5071 | + "severity": "medium", |
| 5072 | + "cwe": [ |
| 5073 | + "CWE-79" |
| 5074 | + ], |
| 5075 | + "identifiers": { |
| 5076 | + "summary": "Froala WYSIWYG Editor 3.2.6 is affected by Cross Site Scripting (XSS). Under certain conditions, a base64 crafted string leads to persistent XSS.", |
| 5077 | + "CVE": [ |
| 5078 | + "CVE-2021-30109" |
| 5079 | + ] |
| 5080 | + }, |
| 5081 | + "info": [ |
| 5082 | + "https://github.com/froala/wysiwyg-editor/releases/tag/v4.0.11" |
| 5083 | + ] |
| 5084 | + }, |
| 5085 | + { |
| 5086 | + "below": "3.2.2", |
| 5087 | + "severity": "medium", |
| 5088 | + "cwe": [ |
| 5089 | + "CWE-79" |
| 5090 | + ], |
| 5091 | + "identifiers": { |
| 5092 | + "summary": "Security issue: XSS via pasted content", |
| 5093 | + "issue": "3880" |
| 5094 | + }, |
| 5095 | + "info": [ |
| 5096 | + "https://froala.com/wysiwyg-editor/changelog/#3.2.2" |
| 5097 | + ] |
| 5098 | + }, |
| 5099 | + { |
| 5100 | + "below": "3.2.2", |
| 5101 | + "severity": "medium", |
| 5102 | + "cwe": [ |
| 5103 | + "CWE-79" |
| 5104 | + ], |
| 5105 | + "identifiers": { |
| 5106 | + "summary": "XSS Issue In Link Insertion", |
| 5107 | + "issue": "3270" |
| 5108 | + }, |
| 5109 | + "info": [ |
| 5110 | + "https://github.com/froala/wysiwyg-editor/issues/3270" |
| 5111 | + ] |
| 5112 | + } |
| 5113 | + ], |
| 5114 | + "extractors": { |
| 5115 | + "uri": [ |
| 5116 | + "/froala-editor/(§§version§§)/", |
| 5117 | + "/froala-editor@(§§version§§)/" |
| 5118 | + ], |
| 5119 | + "filecontent": [ |
| 5120 | + "/\\*![\\s]+\\* froala_editor v(§§version§§)", |
| 5121 | + "VERSION:\"(§§version§§)\",INSTANCES:\\[\\],OPTS_MAPPING:\\{\\}" |
| 5122 | + ] |
| 5123 | + } |
| 5124 | + }, |
| 5125 | + "pendo": { |
| 5126 | + "vulnerabilities": [ |
| 5127 | + { |
| 5128 | + "below": "2.15.18", |
| 5129 | + "severity": "medium", |
| 5130 | + "cwe": [ |
| 5131 | + "CWE-79" |
| 5132 | + ], |
| 5133 | + "identifiers": { |
| 5134 | + "summary": "Patched XSS vulnerability around script loading", |
| 5135 | + "retid": "74" |
| 5136 | + }, |
| 5137 | + "info": [ |
| 5138 | + "https://developers.pendo.io/agent-version-2-15-18/" |
| 5139 | + ] |
| 5140 | + } |
| 5141 | + ], |
| 5142 | + "extractors": { |
| 5143 | + "filecontent": [ |
| 5144 | + "// Pendo Agent Wrapper\n//[\\s]+Environment:[\\s]+[^\n]+\n// Agent Version:[\\s]+(§§version§§)" |
| 5145 | + ] |
| 5146 | + } |
| 5147 | + }, |
5012 | 5148 | "dont check": { |
5013 | 5149 | "extractors": { |
5014 | 5150 | "uri": [ |
|
0 commit comments