[
https://issues.apache.org/jira/browse/HBASE-30442?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
ASF GitHub Bot updated HBASE-30442:
-----------------------------------
Labels: pull-request-available (was: )
> Upgrade brace-expansion and fast-uri in website to fix known security
> vulnerabilities
> -------------------------------------------------------------------------------------
>
> Key: HBASE-30442
> URL: https://issues.apache.org/jira/browse/HBASE-30442
> Project: HBase
> Issue Type: Task
> Components: dependencies, security, website
> Reporter: Dávid Paksy
> Assignee: Dávid Paksy
> Priority: Major
> Labels: pull-request-available
>
> npm audit report before:
>
> {noformat}
> # npm audit report
> brace-expansion <=1.1.20 || 4.0.0 - 5.0.11
> Severity: high
> brace-expansion: Quadratic-time expansion of the `{a},b}` rewrite causes CPU
> denial of service - https://github.com/advisories/GHSA-q2hr-2g5m-vwhr
> brace-expansion: Quadratic-time expansion of the `{a},b}` rewrite causes CPU
> denial of service - https://github.com/advisories/GHSA-q2hr-2g5m-vwhr
> brace-expansion: DoS via uncontrolled recursion on nested brace groups
> causing stack exhaustion - https://github.com/advisories/GHSA-qhr7-859c-m2p7
> brace-expansion: DoS via uncontrolled recursion on nested brace groups
> causing stack exhaustion - https://github.com/advisories/GHSA-qhr7-859c-m2p7
> brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing
> stack exhaustion - https://github.com/advisories/GHSA-6j4f-fj2g-mc7p
> brace-expansion: DoS via uncontrolled recursion in parseCommaParts causing
> stack exhaustion - https://github.com/advisories/GHSA-6j4f-fj2g-mc7p
> fix available via `npm audit fix`
> node_modules/brace-expansion
> node_modules/serve-handler/node_modules/brace-expansion
> fast-uri 3.0.0 - 3.1.7
> Severity: moderate
> fast-uri vulnerable to inconsistent host case normalization via
> percent-encoded octets - https://github.com/advisories/GHSA-hrr3-gc8f-f4qj
> fix available via `npm audit fix`
> node_modules/fast-uri
> 2 vulnerabilities (1 moderate, 1 high)
> To address all issues, run:
> npm audit fix
> {noformat}
--
This message was sent by Atlassian Jira
(v8.20.10#820010)