Skip to content

Commit f43ce91

Browse files
authored
Merge pull request #233 from ejarocki-cloudlinux/doc/request-lodash-CVEs
Add Resolved CVEs section to Angular, Request and Lodash
2 parents 873a7b1 + 1b6eb3d commit f43ce91

File tree

3 files changed

+125
-0
lines changed

3 files changed

+125
-0
lines changed

docs/els-for-runtimes-and-libraries/angular/README.md

Lines changed: 62 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -403,6 +403,68 @@ If you have already installed a package with a `tuxcare.1` suffix and want to up
403403

404404
</CodeWithCopy>
405405

406+
## Resolved CVEs
407+
408+
Fixes for the following vulnerabilities are available in ELS for Angular from TuxCare versions:
409+
410+
<TableTabs label="Choose Angular version: " >
411+
412+
<template #Angular__14>
413+
414+
| CVE ID | CVE Type | Severity | Affected Library | Vulnerable Versions |
415+
| :------------: | :------: | :------: | :---------------: | :-----------------: |
416+
| CVE-2024-29180 | Transitive | High | webpack-dev-middleware | <=5.3.3 |
417+
| CVE-2025-27789 | Transitive | Moderate | @babel/runtime | <7.26.10 |
418+
| GHSA-67mh-4wv8-2f99 | Transitive | Moderate | esbuild | <=0.24.2 |
419+
| CVE-2025-30360 | Transitive | Moderate | webpack-dev-server | <=5.2.0 |
420+
| CVE-2025-30359 | Transitive | Moderate | webpack-dev-server | <=5.2.0 |
421+
| CVE-2024-43788 | Transitive | Moderate | webpack | 5.0.0-alpha.0 - 5.93.0 |
422+
| CVE-2025-54798 | Transitive | Low | tmp | <=0.2.3 |
423+
424+
</template>
425+
426+
<template #Angular__15>
427+
428+
| CVE ID | CVE Type | Severity | Affected Library | Vulnerable Versions |
429+
| :------------: | :------: | :------: | :---------------: | :-----------------: |
430+
| CVE-2025-27789 | Transitive | Moderate | @babel/runtime | <7.26.10 |
431+
| GHSA-67mh-4wv8-2f99 | Transitive | Moderate | esbuild | <=0.24.2 |
432+
| CVE-2025-30360 | Transitive | Moderate | webpack-dev-server | <=5.2.0 |
433+
| CVE-2025-30359 | Transitive | Moderate | webpack-dev-server | <=5.2.0 |
434+
| CVE-2024-43788 | Transitive | Moderate | webpack | 5.0.0-alpha.0 - 5.93.0 |
435+
| CVE-2025-54798 | Transitive | Low | tmp | <=0.2.3 |
436+
437+
</template>
438+
439+
<template #Angular__16>
440+
441+
| CVE ID | CVE Type | Severity | Affected Library | Vulnerable Versions |
442+
| :------------: | :------: | :------: | :---------------: | :-----------------: |
443+
| CVE-2025-27789 | Transitive | Moderate | @babel/runtime | <7.26.10 |
444+
| GHSA-67mh-4wv8-2f99 | Transitive | Moderate | esbuild | <=0.24.2 |
445+
| CVE-2025-32997 | Transitive | Moderate | http-proxy-middleware | 1.3.0 - 2.0.8 |
446+
| CVE-2025-30360 | Transitive | Moderate | webpack-dev-server | <=5.2.0 |
447+
| CVE-2025-30359 | Transitive | Moderate | webpack-dev-server | <=5.2.0 |
448+
| CVE-2025-54798 | Transitive | Low | tmp | <=0.2.3 |
449+
450+
</template>
451+
452+
<template #Angular__17>
453+
454+
| CVE ID | CVE Type | Severity | Affected Library | Vulnerable Versions |
455+
| :------------: | :------: | :------: | :---------------: | :-----------------: |
456+
| GHSA-67mh-4wv8-2f99 | Transitive | Moderate | esbuild | <=0.24.2 |
457+
| CVE-2025-32997 | Transitive | Moderate | http-proxy-middleware | 1.3.0 - 2.0.8 |
458+
| CVE-2025-30360 | Transitive | Moderate | webpack-dev-server | <=5.2.0 |
459+
| CVE-2025-30359 | Transitive | Moderate | webpack-dev-server | <=5.2.0 |
460+
| CVE-2025-54798 | Transitive | Low | tmp | <=0.2.3 |
461+
462+
</template>
463+
464+
</TableTabs>
465+
466+
If you are interested in the TuxCare Endless Lifecycle Support, contact [[email protected]](mailto:[email protected]).
467+
406468
<script setup>
407469
const Angular19WithSSR =
408470
`"dependencies": {

docs/els-for-runtimes-and-libraries/lodash/README.md

Lines changed: 35 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -156,3 +156,38 @@ If you have already installed a package with a `tuxcare.1` suffix and want to up
156156
```
157157

158158
</CodeWithCopy>
159+
160+
## Resolved CVEs
161+
162+
Fixes for the following vulnerabilities are available in ELS for Lodash from TuxCare versions:
163+
164+
<TableTabs label="Choose Lodash version: " >
165+
166+
<template #Lodash__4.5.0>
167+
168+
| CVE ID | CVE Type | Severity | Affected Libraries | Vulnerable Version |
169+
| :------------: | :------: |:--------:| :-----------------: |:------------------:|
170+
| CVE-2021-23337 | Direct | High | Lodash | <4.17.20 |
171+
172+
</template>
173+
174+
<template #Lodash__4.17.15>
175+
176+
| CVE ID | CVE Type | Severity | Affected Libraries | Vulnerable Version |
177+
| :------------: | :------: | :------: | :-----------------: | :----------------: |
178+
| CVE-2020-8203 | Direct | High | Lodash | <4.17.20 |
179+
180+
</template>
181+
182+
<template #Lodash__4.17.19>
183+
184+
| CVE ID | CVE Type | Severity | Affected Libraries | Vulnerable Version |
185+
| :------------: | :------: | :------: | :-----------------: |:------------------:|
186+
| CVE-2020-8203 | Direct | High | Lodash | <4.17.20 |
187+
188+
</template>
189+
190+
</TableTabs>
191+
192+
193+
If you are interested in the TuxCare Endless Lifecycle Support, contact [[email protected]](mailto:[email protected]).

docs/els-for-runtimes-and-libraries/request/README.md

Lines changed: 28 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -142,3 +142,31 @@ If you have already installed a package with a `tuxcare.1` suffix and want to up
142142
```
143143

144144
</CodeWithCopy>
145+
146+
## Resolved CVEs
147+
148+
Fixes for the following vulnerabilities are available in ELS for Request from TuxCare versions:
149+
150+
<TableTabs label="Choose Request version: " >
151+
152+
<template #Request__2.88.0>
153+
154+
| CVE ID | CVE Type | Severity | Affected Libraries | Vulnerable Version |
155+
| :------------: |:----------:|:--------:|:------------------:|:------------------:|
156+
| CVE-2025-7783 | Transitive | Critical | Form-Data | < 2.5.4 |
157+
| CVE-2023-28155 | Direct | Medium | Request | <=2.88.1 |
158+
159+
</template>
160+
161+
<template #Request__2.88.2>
162+
163+
| CVE ID | CVE Type | Severity | Affected Libraries | Vulnerable Version |
164+
| :------------: | :------: |:--------:|:------------------:| :----------------: |
165+
| CVE-2025-7783 | Transitive | Critical | Form-Data | < 2.5.4 |
166+
167+
</template>
168+
169+
</TableTabs>
170+
171+
172+
If you are interested in the TuxCare Endless Lifecycle Support, contact [[email protected]](mailto:[email protected]).

0 commit comments

Comments
 (0)