Vulnerabilities introduced via older version of bestzip npm package.
/vuln-node-app$ npm audit
# npm audit report
bestzip <=2.1.6
Severity: critical
Command Injection in bestzip - https://github.com/advisories/GHSA-4qqc-mp5f-ccv4
Command injection in bestzip - https://github.com/advisories/GHSA-6xv6-jpvw-cx6q
Depends on vulnerable versions of yargs
fix available via `npm audit fix --force`
Will install [email protected], which is a breaking change
node_modules/bestzip
yargs-parser 6.0.0 - 13.1.1
Severity: moderate
yargs-parser Vulnerable to Prototype Pollution - https://github.com/advisories/GHSA-p9pc-299p-vxgp
fix available via `npm audit fix --force`
Will install [email protected], which is a breaking change
node_modules/yargs-parser
yargs 8.0.0-candidate.0 - 12.0.5
Depends on vulnerable versions of yargs-parser
node_modules/yargs
3 vulnerabilities (2 moderate, 1 critical)
To address all issues (including breaking changes), run:
npm audit fix --force
/vuln-node-app$ orca-cli fs scan ./
____ ___ _____ ___ ____ ____ _____ __ __ ___ ____ ________ __
/ __ \ / _ \ / ___// _ | / __// __// ___// / / // _ \ / _//_ __/\ \/ /
/ /_/ // , _// /__ / __ | _\ \ / _/ / /__ / /_/ // , _/_/ / / / \ /
\____//_/|_| \___//_/ |_| /___//___/ \___/ \____//_/|_|/___/ /_/ /_/
โ Performing file system scanning for security risks
โ Performing results analysis and policy decision (via Orca Cloud)
========================================================================
VULNERABILITIES
npm (./package-lock.json)
[TOTAL: 3 | CRITICAL: 1 | HIGH: 1 | MEDIUM: 1 | LOW: 0 | UNKNOWN: 0]
โญโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโฌโโโโโโโโฌโโโโโโโโฌโโโโโโโโโฎ
โ PACKAGE โ VULNERABILITY ID โ INSTALLED VERSION โ FIXED VERSION โ SEVERITY โ CVSS2 โ CVSS3 โ STATUS โ
โโโโโโโโโโโโโโโโผโโโโโโโโโโโโโโโโโโโโโโผโโโโโโโโโโโโโโโโโโโโผโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโผโโโโโโโโโโโผโโโโโโโโผโโโโโโโโผโโโโโโโโโค
โ bestzip โ GHSA-4qqc-mp5f-ccv4 โ 1.1.6 โ 2.1.7 โ CRITICAL โ โ โ FAILED โ
โโโโโโโโโโโโโโโโผโโโโโโโโโโโโโโโโโโโโโโผโโโโโโโโโโโโโโโโโโโโผโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโผโโโโโโโโโโโผโโโโโโโโผโโโโโโโโผโโโโโโโโโค
โ bestzip โ CVE-2020-7730 โ 1.1.6 โ 2.1.7 โ HIGH โ 7.5 โ โ FAILED โ
โโโโโโโโโโโโโโโโผโโโโโโโโโโโโโโโโโโโโโโผโโโโโโโโโโโโโโโโโโโโผโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโผโโโโโโโโโโโผโโโโโโโโผโโโโโโโโผโโโโโโโโโค
โ yargs-parser โ CVE-2020-7608 โ 11.1.1 โ 13.1.2, 15.0.1, 18.1.1, 5.0.1 โ MEDIUM โ 4.6 โ 5.3 โ FAILED โ
โฐโโโโโโโโโโโโโโโดโโโโโโโโโโโโโโโโโโโโโโดโโโโโโโโโโโโโโโโโโโโดโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโดโโโโโโโโโโโดโโโโโโโโดโโโโโโโโดโโโโโโโโโฏ