Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update dependency urijs to v1.19.9 #20

Open
wants to merge 1 commit into
base: dev
Choose a base branch
from

Conversation

mend-for-github-com[bot]
Copy link

@mend-for-github-com mend-for-github-com bot commented Nov 30, 2022

This PR contains the following updates:

Package Type Update Change
urijs (source) dependencies patch 1.19.2 -> 1.19.9

By merging this PR, the below vulnerabilities will be automatically resolved:

Severity CVSS Score CVE
High High 7.5 CVE-2021-27516
Medium Medium 6.5 CVE-2020-26291
Medium Medium 6.5 CVE-2022-0613
Medium Medium 6.1 CVE-2021-3647
Medium Medium 6.1 CVE-2022-0868
Medium Medium 6.1 CVE-2022-1233
Medium Medium 6.1 CVE-2022-1243
Medium Medium 5.3 CVE-2022-24723

Release Notes

medialize/URI.js

v1.19.9

Compare Source

v1.19.8

Compare Source

v1.19.7

Compare Source

  • SECURITY fixing URI.parseQuery() to prevent overwriting __proto__ in parseQuery() - disclosed privately by @​NewEraCracker
  • SECURITY fixing URI.parse() to handle variable amounts of \ and / in scheme delimiter as Node and Browsers do - disclosed privately by ready-research via https://huntr.dev/
  • removed obsolete build tools
  • updated jQuery versions (verifying compatibility with 1.12.4, 2.2.4, 3.6.0)

v1.19.6

Compare Source

  • SECURITY fixing URI.parse() to rewrite \ in scheme delimiter to / as Node and Browsers do - disclosed privately by Yaniv Nizry from the CxSCA AppSec team at Checkmarx

v1.19.5

Compare Source

  • dropping jquery.URI.js from minified bundle accidentally added since v1.19.3 - Issue #​404

v1.19.4

Compare Source

v1.19.3

Compare Source


  • If you want to rebase/retry this PR, click this checkbox.

@mend-for-github-com mend-for-github-com bot added the security fix Security fix generated by Mend label Nov 30, 2022
@mend-for-github-com mend-for-github-com bot force-pushed the whitesource-remediate/urijs-1.x-lockfile branch 2 times, most recently from 410bd74 to 76e401f Compare December 3, 2022 01:35
@mend-for-github-com mend-for-github-com bot changed the title Update dependency urijs to v1.19.9 Update dependency urijs to v1.19.9 - autoclosed Dec 4, 2022
@mend-for-github-com mend-for-github-com bot deleted the whitesource-remediate/urijs-1.x-lockfile branch December 4, 2022 08:01
@mend-for-github-com mend-for-github-com bot changed the title Update dependency urijs to v1.19.9 - autoclosed Update dependency urijs to v1.19.9 Dec 4, 2022
@mend-for-github-com mend-for-github-com bot reopened this Dec 4, 2022
@mend-for-github-com mend-for-github-com bot restored the whitesource-remediate/urijs-1.x-lockfile branch December 4, 2022 08:20
@mend-for-github-com mend-for-github-com bot force-pushed the whitesource-remediate/urijs-1.x-lockfile branch 6 times, most recently from 68c83ab to 06783b8 Compare December 11, 2022 04:28
@mend-for-github-com mend-for-github-com bot force-pushed the whitesource-remediate/urijs-1.x-lockfile branch 2 times, most recently from b06b0fb to bc4f2f2 Compare December 15, 2022 12:40
@mend-for-github-com mend-for-github-com bot force-pushed the whitesource-remediate/urijs-1.x-lockfile branch 3 times, most recently from b25ec86 to c48e916 Compare December 28, 2022 17:23
@mend-for-github-com mend-for-github-com bot force-pushed the whitesource-remediate/urijs-1.x-lockfile branch from c48e916 to b06a89a Compare December 29, 2022 00:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
security fix Security fix generated by Mend
Projects
None yet
0 participants