[Snyk] Upgrade @angular/pwa from 0.12.4 to 0.1102.14 by snyk-bot · Pull Request #25 · GetTerminus/ui-stackblitz-starter
Snyk has created this PR to upgrade @angular/pwa from 0.12.4 to 0.1102.14.
ℹ️ Keep your dependencies up-to-date. This makes it easier to fix existing vulnerabilities and to more quickly identify and fix newly disclosed vulnerabilities when they affect your project.
- The recommended version is 248 versions ahead of your current version.
- The recommended version was released 5 months ago, on 2021-06-03.
The recommended version fixes:
| Severity | Issue | PriorityScore (*) | Exploit Maturity |
|---|---|---|---|
| Arbitrary File Write SNYK-JS-TAR-1579155 |
425/1000 Why? CVSS 8.5 |
No Known Exploit | |
| Arbitrary File Write SNYK-JS-TAR-1579152 |
425/1000 Why? CVSS 8.5 |
No Known Exploit | |
| Arbitrary File Write SNYK-JS-TAR-1579147 |
425/1000 Why? CVSS 8.5 |
No Known Exploit | |
| Arbitrary File Overwrite SNYK-JS-TAR-1536531 |
425/1000 Why? CVSS 8.5 |
No Known Exploit | |
| Arbitrary File Overwrite SNYK-JS-TAR-1536528 |
425/1000 Why? CVSS 8.5 |
No Known Exploit | |
| Prototype Pollution SNYK-JS-SETVALUE-450213 |
425/1000 Why? CVSS 8.5 |
Proof of Concept | |
| Prototype Pollution SNYK-JS-SETVALUE-1540541 |
425/1000 Why? CVSS 8.5 |
No Known Exploit | |
| Prototype Pollution SNYK-JS-SETVALUE-450213 |
425/1000 Why? CVSS 8.5 |
Proof of Concept | |
| Prototype Pollution SNYK-JS-SETVALUE-1540541 |
425/1000 Why? CVSS 8.5 |
No Known Exploit | |
| Prototype Pollution SNYK-JS-INI-1048974 |
425/1000 Why? CVSS 8.5 |
Proof of Concept | |
| Regular Expression Denial of Service (ReDoS) SNYK-JS-ANSIREGEX-1583908 |
425/1000 Why? CVSS 8.5 |
Proof of Concept | |
| Regular Expression Denial of Service (ReDoS) SNYK-JS-GLOBPARENT-1016905 |
425/1000 Why? CVSS 8.5 |
Proof of Concept | |
| Regular Expression Denial of Service (ReDoS) SNYK-JS-TAR-1536758 |
425/1000 Why? CVSS 8.5 |
No Known Exploit | |
| Validation Bypass SNYK-JS-KINDOF-537849 |
425/1000 Why? CVSS 8.5 |
Proof of Concept |
(*) Note that the real score may have changed since the PR was raised.
Note: You are seeing this because you or someone else with access to this repository has authorized Snyk to open upgrade PRs.
🔕 Ignore this dependency or unsubscribe from future upgrade PRs