dogegarden / dogegarden-discordbot Goto Github PK
View Code? Open in Web Editor NEWAn open-source and public Discord bot to view rooms and statistics, plus search for users on DogeHouse.
License: Mozilla Public License 2.0
An open-source and public Discord bot to view rooms and statistics, plus search for users on DogeHouse.
License: Mozilla Public License 2.0
In case you forget to update a libary etc.
An ini encoder/decoder for node
Library home page: https://registry.npmjs.org/ini/-/ini-1.3.5.tgz
Path to dependency file: dogehouse-discordbot/package.json
Path to vulnerable library: dogehouse-discordbot/node_modules/ini/package.json
Dependency Hierarchy:
Found in HEAD commit: 66c1beb6146f88d6725bcc23d1901148b2d20b14
Found in base branch: main
This affects the package ini before 1.3.6. If an attacker submits a malicious INI file to an application that parses it with ini.parse, they will pollute the prototype on the application. This can be exploited further depending on the context.
Publish Date: 2020-12-11
URL: CVE-2020-7788
Base Score Metrics:
Type: Upgrade version
Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-7788
Release Date: 2020-12-11
Fix Resolution: v1.3.6
Step up your Open Source Security Game with WhiteSource here
Would you like a Dogecoin Currency System in the bot, as there are not many features?
A light-weight module that brings window.fetch to node.js
Library home page: https://registry.npmjs.org/node-fetch/-/node-fetch-2.6.0.tgz
Path to dependency file: dogehouse-discordbot/package.json
Path to vulnerable library: dogehouse-discordbot/node_modules/discord.js/node_modules/node-fetch/package.json
Dependency Hierarchy:
Found in HEAD commit: 66c1beb6146f88d6725bcc23d1901148b2d20b14
Found in base branch: main
node-fetch before versions 2.6.1 and 3.0.0-beta.9 did not honor the size option after following a redirect, which means that when a content size was over the limit, a FetchError would never get thrown and the process would end without failure. For most people, this fix will have a little or no impact. However, if you are relying on node-fetch to gate files above a size, the impact could be significant, for example: If you don't double-check the size of the data after fetch() has completed, your JS thread could get tied up doing work on a large file (DoS) and/or cost you money in computing.
Publish Date: 2020-09-10
URL: CVE-2020-15168
Base Score Metrics:
Type: Upgrade version
Origin: GHSA-w7rc-rwvf-8q5r
Release Date: 2020-07-21
Fix Resolution: 2.6.1,3.0.0-beta.9
Step up your Open Source Security Game with WhiteSource here
Expressive query building for MongoDB
Library home page: https://registry.npmjs.org/mquery/-/mquery-3.2.2.tgz
Path to dependency file: dogehouse-discordbot/package.json
Path to vulnerable library: dogehouse-discordbot/node_modules/mquery/package.json
Dependency Hierarchy:
Found in HEAD commit: 66c1beb6146f88d6725bcc23d1901148b2d20b14
Found in base branch: main
lib/utils.js in mquery before 3.2.3 allows a pollution attack because a special property (e.g., proto) can be copied during a merge or clone operation.
Publish Date: 2020-12-11
URL: CVE-2020-35149
Base Score Metrics:
Type: Upgrade version
Origin: https://github.com/aheckmann/mquery/releases/tag/3.2.3
Release Date: 2020-12-11
Fix Resolution: 3.2.3
Step up your Open Source Security Game with WhiteSource here
There is no license
Lodash modular utilities.
Library home page: https://registry.npmjs.org/lodash/-/lodash-4.17.19.tgz
Path to dependency file: dogehouse-discordbot/package.json
Path to vulnerable library: dogehouse-discordbot/node_modules/lodash/package.json
Dependency Hierarchy:
Found in HEAD commit: 66c1beb6146f88d6725bcc23d1901148b2d20b14
Found in base branch: main
Lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function.
Publish Date: 2021-02-15
URL: CVE-2021-23337
Base Score Metrics:
Type: Upgrade version
Origin: lodash/lodash@3469357
Release Date: 2021-02-15
Fix Resolution: lodash - 4.17.21
Step up your Open Source Security Game with WhiteSource here
Lodash modular utilities.
Library home page: https://registry.npmjs.org/lodash/-/lodash-4.17.19.tgz
Path to dependency file: dogehouse-discordbot/package.json
Path to vulnerable library: dogehouse-discordbot/node_modules/lodash/package.json
Dependency Hierarchy:
Found in HEAD commit: 66c1beb6146f88d6725bcc23d1901148b2d20b14
Found in base branch: main
Lodash versions prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the toNumber, trim and trimEnd functions.
WhiteSource Note: After conducting further research, WhiteSource has determined that CVE-2020-28500 only affects environments with versions 4.0.0 to 4.17.20 of Lodash.
Publish Date: 2021-02-15
URL: CVE-2020-28500
Base Score Metrics:
Type: Upgrade version
Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-28500
Release Date: 2021-02-15
Fix Resolution: lodash-4.17.21
Step up your Open Source Security Game with WhiteSource here
Another JSON Schema Validator
Library home page: https://registry.npmjs.org/ajv/-/ajv-6.5.4.tgz
Path to dependency file: dogehouse-discordbot/package.json
Path to vulnerable library: dogehouse-discordbot/node_modules/ajv/package.json
Dependency Hierarchy:
Found in HEAD commit: 66c1beb6146f88d6725bcc23d1901148b2d20b14
Found in base branch: main
An issue was discovered in ajv.validate() in Ajv (aka Another JSON Schema Validator) 6.12.2. A carefully crafted JSON schema could be provided that allows execution of other code by prototype pollution. (While untrusted schemas are recommended against, the worst case of an untrusted schema should be a denial of service, not execution of code.)
Publish Date: 2020-07-15
URL: CVE-2020-15366
Base Score Metrics:
Type: Upgrade version
Origin: https://github.com/ajv-validator/ajv/releases/tag/v6.12.3
Release Date: 2020-07-15
Fix Resolution: ajv - 6.12.3
Step up your Open Source Security Game with WhiteSource here
A declarative, efficient, and flexible JavaScript library for building user interfaces.
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
An Open Source Machine Learning Framework for Everyone
The Web framework for perfectionists with deadlines.
A PHP framework for web artisans
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
Some thing interesting about web. New door for the world.
A server is a program made to process requests and deliver data to clients.
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
Some thing interesting about visualization, use data art
Some thing interesting about game, make everyone happy.
We are working to build community through open source technology. NB: members must have two-factor auth.
Open source projects and samples from Microsoft.
Google ❤️ Open Source for everyone.
Alibaba Open Source for everyone
Data-Driven Documents codes.
China tencent open source team.