Skip to content

Update README.md - #1

Open
Franck-Boost wants to merge 4 commits into
masterfrom
test
Open

Update README.md#1
Franck-Boost wants to merge 4 commits into
masterfrom
test

Conversation

@Franck-Boost

Copy link
Copy Markdown

No description provided.

@boostsecurity-io

Copy link
Copy Markdown

⚠️  56 New Security Findings

The latest commit contains 56 new security findings.

Findings
Dependency: npm / @babel/helpers

Vulnerability Information
Vulnerability Severity CVSS EPSS Affected
Versions
Fixed
Versions
Contains
Malware
Critical
Risk
Description
CVE-2025-27789 Warning 6.2 0.02% 7.26.10
7.26.10
7.26.10
7.26.10
8.0.0-alpha.17
8.0.0-alpha.17
8.0.0-alpha.17
8.0.0-alpha.17
no no Babel has inefficient RegExp complexity in generated code with .replace when transpiling named capturing groups
Dependency Location
https://github.com/FranckBoostOrg/terragoat/blob/e95fe67019608ab6de6a66cb4eb049e29c3bcf70/packages/node/base/package-lock.json
Dependency: npm / @babel/runtime

Vulnerability Information
Vulnerability Severity CVSS EPSS Affected
Versions
Fixed
Versions
Contains
Malware
Critical
Risk
Description
CVE-2025-27789 Warning 6.2 0.02% 7.26.10
7.26.10
7.26.10
7.26.10
8.0.0-alpha.17
8.0.0-alpha.17
8.0.0-alpha.17
8.0.0-alpha.17
no no Babel has inefficient RegExp complexity in generated code with .replace when transpiling named capturing groups
Dependency Location
https://github.com/FranckBoostOrg/terragoat/blob/e95fe67019608ab6de6a66cb4eb049e29c3bcf70/packages/node/base/package-lock.json
Dependency: npm / @babel/traverse

Vulnerability Information
Vulnerability Severity CVSS EPSS Affected
Versions
Fixed
Versions
Contains
Malware
Critical
Risk
Description
CVE-2023-45133 Critical 9.4 0.05% 7.23.2
8.0.0-alpha.4
no no Babel vulnerable to arbitrary code execution when compiling specifically crafted malicious code
Dependency Location
https://github.com/FranckBoostOrg/terragoat/blob/e95fe67019608ab6de6a66cb4eb049e29c3bcf70/packages/node/base/package-lock.json
Dependency: npm / async

Vulnerability Information
Vulnerability Severity CVSS EPSS Affected
Versions
Fixed
Versions
Contains
Malware
Critical
Risk
Description
CVE-2021-43138 Critical 7.8 1.06% 3.2.2
2.6.4
no no Prototype Pollution in async
Dependency Location
https://github.com/FranckBoostOrg/terragoat/blob/e95fe67019608ab6de6a66cb4eb049e29c3bcf70/packages/node/base/package-lock.json
Dependency: npm / body-parser

Vulnerability Information
Vulnerability Severity CVSS EPSS Affected
Versions
Fixed
Versions
Contains
Malware
Critical
Risk
Description
CVE-2024-45590 Critical 7.5 0.50% 1.20.3
no no body-parser vulnerable to denial of service when url encoding is enabled
Dependency Location
https://github.com/FranckBoostOrg/terragoat/blob/e95fe67019608ab6de6a66cb4eb049e29c3bcf70/packages/node/base/package-lock.json
Dependency: npm / braces

Vulnerability Information
Vulnerability Severity CVSS EPSS Affected
Versions
Fixed
Versions
Contains
Malware
Critical
Risk
Description
CVE-2024-4068 Critical 7.5 0.47% 3.0.3
no no Uncontrolled resource consumption in braces
Dependency Location
https://github.com/FranckBoostOrg/terragoat/blob/e95fe67019608ab6de6a66cb4eb049e29c3bcf70/package-lock.json
Dependency: npm / braces

Vulnerability Information
Vulnerability Severity CVSS EPSS Affected
Versions
Fixed
Versions
Contains
Malware
Critical
Risk
Description
CVE-2024-4068 Critical 7.5 0.47% 3.0.3
no no Uncontrolled resource consumption in braces
Dependency Location
https://github.com/FranckBoostOrg/terragoat/blob/e95fe67019608ab6de6a66cb4eb049e29c3bcf70/packages/node/base/package-lock.json
Dependency: npm / cookie

Vulnerability Information
Vulnerability Severity CVSS EPSS Affected
Versions
Fixed
Versions
Contains
Malware
Critical
Risk
Description
CVE-2024-47764 Minor 3.7 0.03% 0.7.0
no no cookie accepts cookie name, path, and domain with out of bounds characters
Dependency Location
https://github.com/FranckBoostOrg/terragoat/blob/e95fe67019608ab6de6a66cb4eb049e29c3bcf70/packages/node/base/package-lock.json
Dependency: npm / cross-spawn

Vulnerability Information
Vulnerability Severity CVSS EPSS Affected
Versions
Fixed
Versions
Contains
Malware
Critical
Risk
Description
CVE-2024-21538 Critical 7.5 0.13% 7.0.5
6.0.6
no no Regular Expression Denial of Service (ReDoS) in cross-spawn
Dependency Location
https://github.com/FranckBoostOrg/terragoat/blob/e95fe67019608ab6de6a66cb4eb049e29c3bcf70/packages/node/base/package-lock.json
Dependency: npm / decode-uri-component

Vulnerability Information
Vulnerability Severity CVSS EPSS Affected
Versions
Fixed
Versions
Contains
Malware
Critical
Risk
Description
CVE-2022-38900 Critical 7.5 0.28% 0.2.1
no no decode-uri-component vulnerable to Denial of Service (DoS)
Dependency Location
https://github.com/FranckBoostOrg/terragoat/blob/e95fe67019608ab6de6a66cb4eb049e29c3bcf70/packages/node/base/package-lock.json
Dependency: pip / django

Vulnerability Information
Vulnerability Severity CVSS EPSS Affected
Versions
Fixed
Versions
Contains
Malware
Critical
Risk
Description
CVE-2010-3082 Warning 6.1 0.41% 1.2.2
no no Cross-site scripting in django
CVE-2010-4534 Critical 6.5 0.55% 1.1.3
1.2.4
no no Improper query string handling in Django
CVE-2010-4535 Warning 7.5 4.75% 1.1.3
1.2.4
no no Improper date handling in Django
CVE-2011-0696 Critical 7.5 2.75% 1.1.4
1.2.5
no no Cross-site request forgery in Django
CVE-2011-0697 Warning 6.1 2.96% 1.1.4
1.2.5
no no Cross-site scripting in django
CVE-2011-0698 Critical 9.1 0.72% 1.1.4
1.2.5
no no Directory traversal in Django
CVE-2011-4136 Warning 4.0 1.02% 1.2.7
1.3.1
no no Session manipulation in Django
CVE-2011-4137 Critical 7.5 1.74% 1.2.7
1.3.1
no no Denial of service in django
CVE-2011-4138 Critical 7.5 0.76% 1.2.7
1.3.1
no no Django Might Allow CSRF Requests via URL Verification
CVE-2011-4139 Critical 7.5 0.57% 1.2.7
1.3.1
no no Django Vulnerable to Cache Poisoning
CVE-2012-3442 Critical 6.1 0.44% 1.3.2
1.4.1
no no Django Allows Redirect via Data URL
CVE-2012-3443 Critical 7.5 1.38% 1.3.2
1.4.1
no no Django Image Field Vulnerable to Image Decompression Bombs
CVE-2012-3444 Critical 7.5 1.19% 1.3.2
1.4.1
no no Django vulnerable to Improper Restriction of Operations within the Bounds of a Memory Buffer
CVE-2014-0472 Critical 9.8 6.89% 1.4.11
1.5.6
1.6.3
no no Code Injection in Django
CVE-2014-0473 Critical 7.5 0.37% 1.4.11
1.5.6
1.6.3
no no Django Reuses Cached CSRF Token
CVE-2014-0474 Critical 9.8 5.23% 1.4.11
1.5.6
1.6.3
no no Django Vulnerable to MySQL Injection
CVE-2014-0480 Critical 7.5 0.48% 1.4.14
1.5.9
1.6.6
no no Django Incorrectly Validates URLs
CVE-2014-0481 Critical 7.5 1.49% 1.4.14
1.5.9
1.6.6
no no Django denial of service via file upload naming
CVE-2014-0482 Warning 6.5 0.61% 1.4.14
1.5.9
1.6.6
1.7c3
no no Django Middleware Enables Session Hijacking
CVE-2014-0483 Warning 5.3 0.37% 1.4.14
1.5.9
1.6.6
1.7c3
no no Django data leakage via querystring manipulation in admin
CVE-2015-0219 Warning 5.3 3.72% 1.4.18
1.6.10
1.7.3
no no Django WSGI Header Spoofing Vulnerability
CVE-2015-0220 Warning 6.1 2.32% 1.4.18
1.6.10
1.7.3
no no Django Cross-site Scripting Vulnerability
CVE-2015-0221 Critical 7.5 8.82% 1.4.18
1.6.10
1.7.3
no no Django DoS in django.views.static.serve
CVE-2015-2241 Warning 6.1 0.26% 1.7.6
1.8b2
no no Django Cross-site Scripting Vulnerability
CVE-2015-2317 Warning 6.1 3.15% 1.4.20
1.6.11
1.7.7
1.8c1
no no Django cross-site scripting (XSS) attack via user-supplied redirect URLs
CVE-2015-5143 Critical 7.5 15.66% 1.4.21
1.7.9
1.8.3
no no Django Denial-of-service by filling session store
CVE-2015-5144 Critical 7.5 1.49% 1.4.21
1.7.9
1.8.3
no no Django Vulnerable to HTTP Response Splitting Attack
CVE-2016-2512 Warning 7.4 0.54% 1.8.10
1.9.3
no no Django XSS Vulnerability
CVE-2016-2513 Minor 3.1 1.08% 1.8.10
1.9.3
no no Django User Enumeration Vulnerability
CVE-2016-6186 Warning 6.1 13.10% 1.8.14
1.9.8
1.10rc1
no no Django Cross-site scripting Vulnerability
CVE-2016-7401 Critical 7.5 2.91% 1.8.15
1.9.10
no no Django CSRF Protection Bypass
CVE-2019-19844 Critical 9.8 15.46% 1.11.27
2.2.9
3.0.1
no no Django Potential account hijack via password reset form
CVE-2020-7471 Critical 9.8 7.77% 1.11.28
2.2.10
3.0.3
no no SQL injection in Django
CVE-2021-33203 Warning 4.9 0.14% 2.2.24
3.1.12
3.2.4
no no Path Traversal in Django
CVE-2022-36359 Critical 8.8 0.40% 3.2.15
4.0.7
no no Django vulnerable to Reflected File Download attack
CVE-2024-45231 Warning 5.3 0.04% 5.1.1
5.0.9
4.2.16
no no Django allows enumeration of user e-mail addresses
Dependency Location
https://github.com/FranckBoostOrg/terragoat/blob/e95fe67019608ab6de6a66cb4eb049e29c3bcf70/packages/requirements.txt
Dependency: pip / django

Vulnerability Information
Vulnerability Severity CVSS EPSS Affected
Versions
Fixed
Versions
Contains
Malware
Critical
Risk
Description
CVE-2010-3082 Warning 6.1 0.41% 1.2.2
no no Cross-site scripting in django
CVE-2010-4534 Critical 6.5 0.55% 1.1.3
1.2.4
no no Improper query string handling in Django
CVE-2010-4535 Warning 7.5 4.75% 1.1.3
1.2.4
no no Improper date handling in Django
CVE-2011-0696 Critical 7.5 2.75% 1.1.4
1.2.5
no no Cross-site request forgery in Django
CVE-2011-0697 Warning 6.1 2.96% 1.1.4
1.2.5
no no Cross-site scripting in django
CVE-2011-0698 Critical 9.1 0.72% 1.1.4
1.2.5
no no Directory traversal in Django
CVE-2011-4136 Warning 4.0 1.02% 1.2.7
1.3.1
no no Session manipulation in Django
CVE-2011-4137 Critical 7.5 1.74% 1.2.7
1.3.1
no no Denial of service in django
CVE-2011-4138 Critical 7.5 0.76% 1.2.7
1.3.1
no no Django Might Allow CSRF Requests via URL Verification
CVE-2011-4139 Critical 7.5 0.57% 1.2.7
1.3.1
no no Django Vulnerable to Cache Poisoning
CVE-2012-3442 Critical 6.1 0.44% 1.3.2
1.4.1
no no Django Allows Redirect via Data URL
CVE-2012-3443 Critical 7.5 1.38% 1.3.2
1.4.1
no no Django Image Field Vulnerable to Image Decompression Bombs
CVE-2012-3444 Critical 7.5 1.19% 1.3.2
1.4.1
no no Django vulnerable to Improper Restriction of Operations within the Bounds of a Memory Buffer
CVE-2014-0472 Critical 9.8 6.89% 1.4.11
1.5.6
1.6.3
no no Code Injection in Django
CVE-2014-0473 Critical 7.5 0.37% 1.4.11
1.5.6
1.6.3
no no Django Reuses Cached CSRF Token
CVE-2014-0474 Critical 9.8 5.23% 1.4.11
1.5.6
1.6.3
no no Django Vulnerable to MySQL Injection
CVE-2014-0480 Critical 7.5 0.48% 1.4.14
1.5.9
1.6.6
no no Django Incorrectly Validates URLs
CVE-2014-0481 Critical 7.5 1.49% 1.4.14
1.5.9
1.6.6
no no Django denial of service via file upload naming
CVE-2014-0482 Warning 6.5 0.61% 1.4.14
1.5.9
1.6.6
1.7c3
no no Django Middleware Enables Session Hijacking
CVE-2014-0483 Warning 5.3 0.37% 1.4.14
1.5.9
1.6.6
1.7c3
no no Django data leakage via querystring manipulation in admin
CVE-2015-0219 Warning 5.3 3.72% 1.4.18
1.6.10
1.7.3
no no Django WSGI Header Spoofing Vulnerability
CVE-2015-0220 Warning 6.1 2.32% 1.4.18
1.6.10
1.7.3
no no Django Cross-site Scripting Vulnerability
CVE-2015-0221 Critical 7.5 8.82% 1.4.18
1.6.10
1.7.3
no no Django DoS in django.views.static.serve
CVE-2015-2241 Warning 6.1 0.26% 1.7.6
1.8b2
no no Django Cross-site Scripting Vulnerability
CVE-2015-2317 Warning 6.1 3.15% 1.4.20
1.6.11
1.7.7
1.8c1
no no Django cross-site scripting (XSS) attack via user-supplied redirect URLs
CVE-2015-5143 Critical 7.5 15.66% 1.4.21
1.7.9
1.8.3
no no Django Denial-of-service by filling session store
CVE-2015-5144 Critical 7.5 1.49% 1.4.21
1.7.9
1.8.3
no no Django Vulnerable to HTTP Response Splitting Attack
CVE-2016-2512 Warning 7.4 0.54% 1.8.10
1.9.3
no no Django XSS Vulnerability
CVE-2016-2513 Minor 3.1 1.08% 1.8.10
1.9.3
no no Django User Enumeration Vulnerability
CVE-2016-6186 Warning 6.1 13.10% 1.8.14
1.9.8
1.10rc1
no no Django Cross-site scripting Vulnerability
CVE-2016-7401 Critical 7.5 2.91% 1.8.15
1.9.10
no no Django CSRF Protection Bypass
CVE-2019-19844 Critical 9.8 15.46% 1.11.27
2.2.9
3.0.1
no no Django Potential account hijack via password reset form
CVE-2020-7471 Critical 9.8 7.77% 1.11.28
2.2.10
3.0.3
no no SQL injection in Django
CVE-2021-33203 Warning 4.9 0.14% 2.2.24
3.1.12
3.2.4
no no Path Traversal in Django
CVE-2022-36359 Critical 8.8 0.40% 3.2.15
4.0.7
no no Django vulnerable to Reflected File Download attack
CVE-2024-45231 Warning 5.3 0.04% 5.1.1
5.0.9
4.2.16
no no Django allows enumeration of user e-mail addresses
Dependency Location
https://github.com/FranckBoostOrg/terragoat/blob/e95fe67019608ab6de6a66cb4eb049e29c3bcf70/packages/sub/.hidden/requirements.txt
Dependency: npm / engine.io

Vulnerability Information
Vulnerability Severity CVSS EPSS Affected
Versions
Fixed
Versions
Contains
Malware
Critical
Risk
Description
CVE-2022-21676 Critical 7.5 0.58% 4.1.2
5.2.1
6.1.1
no no Uncaught Exception in engine.io
CVE-2022-41940 Warning 6.5 3.31% 3.6.1
6.2.1
no no Uncaught exception in engine.io
CVE-2023-31125 Warning 6.5 0.61% 6.4.2
no no engine.io Uncaught Exception vulnerability
Dependency Location
https://github.com/FranckBoostOrg/terragoat/blob/e95fe67019608ab6de6a66cb4eb049e29c3bcf70/packages/node/base/package-lock.json
Dependency: npm / esbuild

Vulnerability Information
Vulnerability Severity CVSS EPSS Affected
Versions
Fixed
Versions
Contains
Malware
Critical
Risk
Description
GHSA-67mh-4wv8-2f99 Warning 5.3 0.25.0
no no esbuild enables any website to send any requests to the development server and read the response
Dependency Location
https://github.com/FranckBoostOrg/terragoat/blob/e95fe67019608ab6de6a66cb4eb049e29c3bcf70/packages/node/base/package-lock.json
Dependency: npm / express

Vulnerability Information
Vulnerability Severity CVSS EPSS Affected
Versions
Fixed
Versions
Contains
Malware
Critical
Risk
Description
CVE-2024-29041 Warning 6.1 0.09% 4.19.2
5.0.0-beta.3
no no Express.js Open Redirect in malformed URLs
CVE-2024-43796 Minor 5.0 0.02% 4.20.0
5.0.0
no no express vulnerable to XSS via response.redirect()
Dependency Location
https://github.com/FranckBoostOrg/terragoat/blob/e95fe67019608ab6de6a66cb4eb049e29c3bcf70/packages/node/base/package-lock.json
Dependency: npm / follow-redirects

Vulnerability Information
Vulnerability Severity CVSS EPSS Affected
Versions
Fixed
Versions
Contains
Malware
Critical
Risk
Description
CVE-2022-0155 Critical 8.0 0.93% 1.14.7
no no Exposure of sensitive information in follow-redirects
CVE-2022-0536 Warning 5.9 0.06% 1.14.8
no no Exposure of Sensitive Information to an Unauthorized Actor in follow-redirects
CVE-2023-26159 Warning 6.1 0.06% 1.15.4
no no Follow Redirects improperly handles URLs in the url.parse() function
CVE-2024-28849 Warning 6.5 0.12% 1.15.6
no no follow-redirects' Proxy-Authorization header kept across hosts
Dependency Location
https://github.com/FranckBoostOrg/terragoat/blob/e95fe67019608ab6de6a66cb4eb049e29c3bcf70/packages/node/base/package-lock.json
Dependency: npm / got

Vulnerability Information
Vulnerability Severity CVSS EPSS Affected
Versions
Fixed
Versions
Contains
Malware
Critical
Risk
Description
CVE-2022-33987 Warning 5.3 0.72% 12.1.0
11.8.5
no no Got allows a redirect to a UNIX socket
Dependency Location
https://github.com/FranckBoostOrg/terragoat/blob/e95fe67019608ab6de6a66cb4eb049e29c3bcf70/package-lock.json
Dependency: npm / http-cache-semantics

Vulnerability Information
Vulnerability Severity CVSS EPSS Affected
Versions
Fixed
Versions
Contains
Malware
Critical
Risk
Description
CVE-2022-25881 Critical 7.5 0.12% 4.1.1
4.1.1
no no http-cache-semantics vulnerable to Regular Expression Denial of Service
Dependency Location
https://github.com/FranckBoostOrg/terragoat/blob/e95fe67019608ab6de6a66cb4eb049e29c3bcf70/package-lock.json
Dependency: npm / http-cache-semantics

Vulnerability Information
Vulnerability Severity CVSS EPSS Affected
Versions
Fixed
Versions
Contains
Malware
Critical
Risk
Description
CVE-2022-25881 Critical 7.5 0.12% 4.1.1
4.1.1
no no http-cache-semantics vulnerable to Regular Expression Denial of Service
Dependency Location
https://github.com/FranckBoostOrg/terragoat/blob/e95fe67019608ab6de6a66cb4eb049e29c3bcf70/packages/node/base/package-lock.json
Dependency: npm / http-proxy-middleware

Vulnerability Information
Vulnerability Severity CVSS EPSS Affected
Versions
Fixed
Versions
Contains
Malware
Critical
Risk
Description
CVE-2024-21536 Critical 7.5 0.14% 2.0.7
3.0.3
no no Denial of service in http-proxy-middleware
CVE-2025-32996 Warning 4.0 0.05% 2.0.8
3.0.4
no no http-proxy-middleware can call writeBody twice because "else if" is not used
CVE-2025-32997 Warning 4.0 0.04% 2.0.9
3.0.5
no no http-proxy-middleware allows fixRequestBody to proceed even if bodyParser has failed
Dependency Location
https://github.com/FranckBoostOrg/terragoat/blob/e95fe67019608ab6de6a66cb4eb049e29c3bcf70/packages/node/base/package-lock.json
Dependency: npm / ip

Vulnerability Information
Vulnerability Severity CVSS EPSS Affected
Versions
Fixed
Versions
Contains
Malware
Critical
Risk
Description
CVE-2023-42282 Minor 9.8 0.25% 2.0.1
1.1.9
no no NPM IP package incorrectly identifies some private IP addresses as public
Dependency Location
https://github.com/FranckBoostOrg/terragoat/blob/e95fe67019608ab6de6a66cb4eb049e29c3bcf70/packages/node/base/package-lock.json
Dependency: npm / json5

Vulnerability Information
Vulnerability Severity CVSS EPSS Affected
Versions
Fixed
Versions
Contains
Malware
Critical
Risk
Description
CVE-2022-46175 Critical 7.1 40.60% 2.2.2
1.0.2
no no Prototype Pollution in JSON5 via Parse Method
Dependency Location
https://github.com/FranckBoostOrg/terragoat/blob/e95fe67019608ab6de6a66cb4eb049e29c3bcf70/packages/node/base/package-lock.json
Dependency: npm / jszip

Vulnerability Information
Vulnerability Severity CVSS EPSS Affected
Versions
Fixed
Versions
Contains
Malware
Critical
Risk
Description
CVE-2022-48285 Warning 7.3 0.42% 3.8.0
no no JSZip contains Path Traversal via loadAsync
Dependency Location
https://github.com/FranckBoostOrg/terragoat/blob/e95fe67019608ab6de6a66cb4eb049e29c3bcf70/packages/node/base/package-lock.json
Dependency: npm / karma

Vulnerability Information
Vulnerability Severity CVSS EPSS Affected
Versions
Fixed
Versions
Contains
Malware
Critical
Risk
Description
CVE-2021-23495 Warning 5.4 0.24% 6.3.16
no no Open redirect in karma
CVE-2022-0437 Warning 6.1 8.82% 6.3.14
no no Cross-site Scripting in karma
Dependency Location
https://github.com/FranckBoostOrg/terragoat/blob/e95fe67019608ab6de6a66cb4eb049e29c3bcf70/packages/node/base/package-lock.json
Dependency: npm / loader-utils

Vulnerability Information
Vulnerability Severity CVSS EPSS Affected
Versions
Fixed
Versions
Contains
Malware
Critical
Risk
Description
CVE-2022-37599 Critical 7.5 3.17% 1.4.2
2.0.4
3.2.1
no no loader-utils is vulnerable to Regular Expression Denial of Service (ReDoS)
CVE-2022-37601 Critical 9.8 15.73% 2.0.3
1.4.1
no no Prototype pollution in webpack loader-utils
CVE-2022-37603 Critical 7.5 0.85% 1.4.2
2.0.4
3.2.1
no no loader-utils is vulnerable to Regular Expression Denial of Service (ReDoS) via url variable
Dependency Location
https://github.com/FranckBoostOrg/terragoat/blob/e95fe67019608ab6de6a66cb4eb049e29c3bcf70/packages/node/base/package-lock.json
Dependency: npm / log4js

Vulnerability Information
Vulnerability Severity CVSS EPSS Affected
Versions
Fixed
Versions
Contains
Malware
Critical
Risk
Description
CVE-2022-21704 Warning 5.5 0.03% 6.4.0
no no Incorrect Default Permissions in log4js
Dependency Location
https://github.com/FranckBoostOrg/terragoat/blob/e95fe67019608ab6de6a66cb4eb049e29c3bcf70/packages/node/base/package-lock.json
Dependency: npm / micromatch

Vulnerability Information
Vulnerability Severity CVSS EPSS Affected
Versions
Fixed
Versions
Contains
Malware
Critical
Risk
Description
CVE-2024-4067 Warning 5.3 0.37% 4.0.8
no no Regular Expression Denial of Service (ReDoS) in micromatch
Dependency Location
https://github.com/FranckBoostOrg/terragoat/blob/e95fe67019608ab6de6a66cb4eb049e29c3bcf70/packages/node/base/package-lock.json
Dependency: npm / minimatch

Vulnerability Information
Vulnerability Severity CVSS EPSS Affected
Versions
Fixed
Versions
Contains
Malware
Critical
Risk
Description
CVE-2022-3517 Critical 7.5 0.46% 3.0.5
no no minimatch ReDoS vulnerability
Dependency Location
https://github.com/FranckBoostOrg/terragoat/blob/e95fe67019608ab6de6a66cb4eb049e29c3bcf70/packages/node/base/package-lock.json
Dependency: npm / minimist

Vulnerability Information
Vulnerability Severity CVSS EPSS Affected
Versions
Fixed
Versions
Contains
Malware
Critical
Risk
Description
CVE-2021-44906 Critical 9.8 0.76% 0.2.1
1.2.3
no no Prototype Pollution in minimist
Dependency Location
https://github.com/FranckBoostOrg/terragoat/blob/e95fe67019608ab6de6a66cb4eb049e29c3bcf70/packages/node/base/package-lock.json
Dependency: npm / nanoid

Vulnerability Information
Vulnerability Severity CVSS EPSS Affected
Versions
Fixed
Versions
Contains
Malware
Critical
Risk
Description
CVE-2021-23566 Warning 5.5 0.03% 3.1.31
no no Exposure of Sensitive Information to an Unauthorized Actor in nanoid
CVE-2024-55565 Warning 4.3 0.03% 5.0.9
3.3.8
no no Predictable results in nanoid generation when given non-integer values
Dependency Location
https://github.com/FranckBoostOrg/terragoat/blob/e95fe67019608ab6de6a66cb4eb049e29c3bcf70/packages/node/base/package-lock.json
Dependency: npm / node-fetch

Vulnerability Information
Vulnerability Severity CVSS EPSS Affected
Versions
Fixed
Versions
Contains
Malware
Critical
Risk
Description
CVE-2022-0235 Critical 8.8 0.53% 3.1.1
2.6.7
no no node-fetch forwards secure headers to untrusted sites
Dependency Location
https://github.com/FranckBoostOrg/terragoat/blob/e95fe67019608ab6de6a66cb4eb049e29c3bcf70/packages/node/base/package-lock.json
Dependency: npm / node-forge

Vulnerability Information
Vulnerability Severity CVSS EPSS Affected
Versions
Fixed
Versions
Contains
Malware
Critical
Risk
Description
CVE-2022-0122 Warning 6.1 0.53% 1.0.0
no no Open Redirect in node-forge
CVE-2022-24771 Critical 7.5 0.11% 1.3.0
no no Improper Verification of Cryptographic Signature in node-forge
CVE-2022-24772 Critical 7.5 0.12% 1.3.0
no no Improper Verification of Cryptographic Signature in node-forge
CVE-2022-24773 Warning 5.3 0.06% 1.3.0
no no Improper Verification of Cryptographic Signature in node-forge
GHSA-5rrq-pxf6-6jx5 Minor -1.0 1.0.0
no no Prototype Pollution in node-forge debug API.
GHSA-gf8q-jrpm-jvxq Minor -1.0 1.0.0
no no URL parsing in node-forge could lead to undesired behavior.
Dependency Location
https://github.com/FranckBoostOrg/terragoat/blob/e95fe67019608ab6de6a66cb4eb049e29c3bcf70/packages/node/base/package-lock.json
Dependency: pom / org.apache.commons:commons-compress

Vulnerability Information
Vulnerability Severity CVSS EPSS Affected
Versions
Fixed
Versions
Contains
Malware
Critical
Risk
Description
CVE-2018-11771 Warning 5.5 0.92% 1.18
no no Moderate severity vulnerability that affects org.apache.commons:commons-compress
CVE-2018-1324 Warning 5.5 0.28% 1.16
3.7.4
no no Apache Commons Compress vulnerable to denial of service due to infinite loop
CVE-2019-12402 Critical 7.5 0.15% 1.19
no no Denial of Service in Apache Commons Compress
CVE-2021-35515 Critical 7.5 0.14% 1.21
no no Excessive Iteration in Compress
CVE-2021-35516 Critical 7.5 0.36% 1.21
no no Improper Handling of Length Parameter Inconsistency in Compress
CVE-2021-35517 Critical 7.5 0.36% 1.21
no no Improper Handling of Length Parameter Inconsistency in Compress
CVE-2021-36090 Critical 7.5 0.28% 1.21
no no Improper Handling of Length Parameter Inconsistency in Compress
CVE-2024-25710 Warning 5.9 0.01% 1.26.0
no no Apache Commons Compress: Denial of service caused by an infinite loop for a corrupted DUMP file
Dependency Location
https://github.com/FranckBoostOrg/terragoat/blob/e95fe67019608ab6de6a66cb4eb049e29c3bcf70/packages/pom.xml
Dependency: npm / path-to-regexp

Vulnerability Information
Vulnerability Severity CVSS EPSS Affected
Versions
Fixed
Versions
Contains
Malware
Critical
Risk
Description
CVE-2024-45296 Critical 7.5 0.09% 1.9.0
0.1.10
8.0.0
3.3.0
6.3.0
no no path-to-regexp outputs backtracking regular expressions
CVE-2024-52798 Critical 5.3 0.03% 0.1.12
no no Unpatched path-to-regexp ReDoS in 0.1.x
Dependency Location
https://github.com/FranckBoostOrg/terragoat/blob/e95fe67019608ab6de6a66cb4eb049e29c3bcf70/packages/node/base/package-lock.json
Dependency: npm / postcss

Vulnerability Information
Vulnerability Severity CVSS EPSS Affected
Versions
Fixed
Versions
Contains
Malware
Critical
Risk
Description
CVE-2023-44270 Warning 5.3 0.11% 8.4.31
no no PostCSS line return parsing error
Dependency Location
https://github.com/FranckBoostOrg/terragoat/blob/e95fe67019608ab6de6a66cb4eb049e29c3bcf70/packages/node/base/package-lock.json
Dependency: npm / qs

Vulnerability Information
Vulnerability Severity CVSS EPSS Affected
Versions
Fixed
Versions
Contains
Malware
Critical
Risk
Description
CVE-2022-24999 Critical 7.5 2.66% 6.10.3
6.9.7
6.8.3
6.7.3
6.6.1
6.5.3
6.4.1
6.3.3
6.2.4
no no qs vulnerable to Prototype Pollution
Dependency Location
https://github.com/FranckBoostOrg/terragoat/blob/e95fe67019608ab6de6a66cb4eb049e29c3bcf70/packages/node/base/package-lock.json
Dependency: npm / requirejs

Vulnerability Information
Vulnerability Severity CVSS EPSS Affected
Versions
Fixed
Versions
Contains
Malware
Critical
Risk
Description
CVE-2024-38999 Critical 10.0 0.64% 2.3.7
no no jrburke requirejs vulnerable to prototype pollution
Dependency Location
https://github.com/FranckBoostOrg/terragoat/blob/e95fe67019608ab6de6a66cb4eb049e29c3bcf70/packages/node/base/package-lock.json
Dependency: npm / rollup

Vulnerability Information
Vulnerability Severity CVSS EPSS Affected
Versions
Fixed
Versions
Contains
Malware
Critical
Risk
Description
CVE-2024-47068 Critical 6.4 0.02% 3.29.5
4.22.4
2.79.2
no no DOM Clobbering Gadget found in rollup bundled scripts that leads to XSS
Dependency Location
https://github.com/FranckBoostOrg/terragoat/blob/e95fe67019608ab6de6a66cb4eb049e29c3bcf70/packages/node/base/package-lock.json
Dependency: npm / semver

Vulnerability Information
Vulnerability Severity CVSS EPSS Affected
Versions
Fixed
Versions
Contains
Malware
Critical
Risk
Description
CVE-2022-25883 Critical 7.5 0.31% 7.5.2
6.3.1
5.7.2
no no semver vulnerable to Regular Expression Denial of Service
Dependency Location
https://github.com/FranckBoostOrg/terragoat/blob/e95fe67019608ab6de6a66cb4eb049e29c3bcf70/package-lock.json
Dependency: npm / semver

Vulnerability Information
Vulnerability Severity CVSS EPSS Affected
Versions
Fixed
Versions
Contains
Malware
Critical
Risk
Description
CVE-2022-25883 Critical 7.5 0.31% 7.5.2
6.3.1
5.7.2
no no semver vulnerable to Regular Expression Denial of Service
Dependency Location
https://github.com/FranckBoostOrg/terragoat/blob/e95fe67019608ab6de6a66cb4eb049e29c3bcf70/packages/node/base/package-lock.json
Dependency: npm / send

Vulnerability Information
Vulnerability Severity CVSS EPSS Affected
Versions
Fixed
Versions
Contains
Malware
Critical
Risk
Description
CVE-2024-43799 Minor 5.0 0.03% 0.19.0
no no send vulnerable to template injection that can lead to XSS
Dependency Location
https://github.com/FranckBoostOrg/terragoat/blob/e95fe67019608ab6de6a66cb4eb049e29c3bcf70/packages/node/base/package-lock.json
Dependency: npm / serialize-javascript

Vulnerability Information
Vulnerability Severity CVSS EPSS Affected
Versions
Fixed
Versions
Contains
Malware
Critical
Risk
Description
CVE-2024-11831 Warning 5.4 0.03% 6.0.2
no no Cross-site Scripting (XSS) in serialize-javascript
Dependency Location
https://github.com/FranckBoostOrg/terragoat/blob/e95fe67019608ab6de6a66cb4eb049e29c3bcf70/packages/node/base/package-lock.json
Dependency: npm / serve-static

Vulnerability Information
Vulnerability Severity CVSS EPSS Affected
Versions
Fixed
Versions
Contains
Malware
Critical
Risk
Description
CVE-2024-43800 Minor 5.0 0.02% 1.16.0
2.1.0
no no serve-static vulnerable to template injection that can lead to XSS
Dependency Location
https://github.com/FranckBoostOrg/terragoat/blob/e95fe67019608ab6de6a66cb4eb049e29c3bcf70/packages/node/base/package-lock.json
Dependency: npm / shelljs

Vulnerability Information
Vulnerability Severity CVSS EPSS Affected
Versions
Fixed
Versions
Contains
Malware
Critical
Risk
Description
CVE-2022-0144 Critical 7.1 0.05% 0.8.5
no no Improper Privilege Management in shelljs
GHSA-64g7-mvw6-v9qj Warning -1.0 0.8.5
no no Improper Privilege Management in shelljs
Dependency Location
https://github.com/FranckBoostOrg/terragoat/blob/e95fe67019608ab6de6a66cb4eb049e29c3bcf70/packages/node/base/package-lock.json
Dependency: npm / socket.io

Vulnerability Information
Vulnerability Severity CVSS EPSS Affected
Versions
Fixed
Versions
Contains
Malware
Critical
Risk
Description
CVE-2024-38355 Warning 7.3 0.10% 2.5.1
4.6.2
no no socket.io has an unhandled 'error' event
Dependency Location
https://github.com/FranckBoostOrg/terragoat/blob/e95fe67019608ab6de6a66cb4eb049e29c3bcf70/packages/node/base/package-lock.json
Dependency: npm / socket.io-parser

Vulnerability Information
Vulnerability Severity CVSS EPSS Affected
Versions
Fixed
Versions
Contains
Malware
Critical
Risk
Description
CVE-2022-2421 Critical 9.8 0.91% 4.0.5
4.2.1
3.3.3
3.4.2
no no Insufficient validation when decoding a Socket.IO packet
CVE-2023-32695 Warning 7.3 0.16% 4.2.3
3.4.3
3.3.4
no no Insufficient validation when decoding a Socket.IO packet
Dependency Location
https://github.com/FranckBoostOrg/terragoat/blob/e95fe67019608ab6de6a66cb4eb049e29c3bcf70/packages/node/base/package-lock.json
Dependency: npm / tar

Vulnerability Information
Vulnerability Severity CVSS EPSS Affected
Versions
Fixed
Versions
Contains
Malware
Critical
Risk
Description
CVE-2024-28863 Warning 6.5 0.21% 6.2.1
6.2.1
no no Denial of service while parsing a tar file due to lack of folders count validation
Dependency Location
https://github.com/FranckBoostOrg/terragoat/blob/e95fe67019608ab6de6a66cb4eb049e29c3bcf70/packages/node/base/package-lock.json
Dependency: npm / tar-fs

Vulnerability Information
Vulnerability Severity CVSS EPSS Affected
Versions
Fixed
Versions
Contains
Malware
Critical
Risk
Description
CVE-2024-12905 Critical 7.5 1.37% 1.16.4
2.1.2
3.0.8
no no tar-fs Vulnerable to Link Following and Path Traversal via Extracting a Crafted tar File
Dependency Location
https://github.com/FranckBoostOrg/terragoat/blob/e95fe67019608ab6de6a66cb4eb049e29c3bcf70/packages/node/base/package-lock.json
Dependency: npm / terser

Vulnerability Information
Vulnerability Severity CVSS EPSS Affected
Versions
Fixed
Versions
Contains
Malware
Critical
Risk
Description
CVE-2022-25858 Critical 7.5 1.99% 4.8.1
5.14.2
no no Terser insecure use of regular expressions leads to ReDoS
Dependency Location
https://github.com/FranckBoostOrg/terragoat/blob/e95fe67019608ab6de6a66cb4eb049e29c3bcf70/packages/node/base/package-lock.json
Dependency: npm / tough-cookie

Vulnerability Information
Vulnerability Severity CVSS EPSS Affected
Versions
Fixed
Versions
Contains
Malware
Critical
Risk
Description
CVE-2023-26136 Warning 6.5 5.19% 4.1.3
no no tough-cookie Prototype Pollution vulnerability
Dependency Location
https://github.com/FranckBoostOrg/terragoat/blob/e95fe67019608ab6de6a66cb4eb049e29c3bcf70/packages/node/base/package-lock.json

Please note: there are 6 more findings that could not be displayed. Reach out to your security team to learn more.

Not a finding? Ignore it by adding a comment on the line with just the word noboost.

Scanner: boostsecurity - Trivy (Filesystem scanning)

@sonarqubecloud

sonarqubecloud Bot commented Jun 3, 2025

Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant