Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

renovate/37.421.6 package update #22948

Closed
wants to merge 1 commit into from

Conversation

octo-sts[bot]
Copy link
Contributor

@octo-sts octo-sts bot commented Jul 1, 2024

@octo-sts octo-sts bot added request-version-update request for a newer version of a package automated pr labels Jul 1, 2024
Copy link
Contributor Author

octo-sts bot commented Jul 1, 2024

bincapz found risk score equal or higher than '4' for any of the files: Click to expand/collapse

/tmp/bincapz1096779990/packages/x86_64/renovate-37.421.6-r0.apk/usr/local/lib/node_modules/renovate/node_modules/@cdktf/hcl2json/lib/util.js [🚨 CRITICAL]

RISK KEY DESCRIPTION EVIDENCE
CRITICAL evasion/base64/php_functions References multiple PHP functions in base64 form ZW1wdH::$empty
leGVj::$exec
MEDIUM techniques/code_eval evaluate code dynamically using exec() exec(input)
LOW encoding/base64 Supports base64 encoded strings base64

/tmp/bincapz1096779990/packages/x86_64/renovate-37.421.6-r0.apk/usr/local/lib/node_modules/renovate/node_modules/diff/lib/patch/apply.js [🚨 CRITICAL]

RISK KEY DESCRIPTION EVIDENCE
CRITICAL evasion/base64/php_functions References multiple PHP functions in base64 form BcnJhe::$Array
FycmF5::$Array
NvdW50::$count
QXJyYX::$Array
LOW encoding/base64 Supports base64 encoded strings base64

/tmp/bincapz1096779990/packages/x86_64/renovate-37.421.6-r0.apk/usr/local/lib/node_modules/renovate/dist/modules/datasource/deno/index.js [🚨 CRITICAL]

RISK KEY DESCRIPTION EVIDENCE
CRITICAL combo/backdoor/remote_eval Executes code from a remote source exec(pack
MEDIUM net/upload uploads files uploaded_at
LOW ref/site/url contains embedded HTTPS URLs https://apiland.deno.dev/v2/modules/postgres/v0.17.0

/tmp/bincapz1096779990/packages/x86_64/renovate-37.421.6-r0.apk/usr/local/lib/node_modules/renovate/dist/modules/manager/pipenv/extract.js [🚨 CRITICAL]

RISK KEY DESCRIPTION EVIDENCE
CRITICAL combo/backdoor/remote_eval Executes code from a remote source exec(pack
MEDIUM ref/path/dev path reference within /dev /dev/peps/pep-0508/
LOW ref/site/url contains embedded HTTPS URLs https://www.python.org/dev/peps/pep-0508/

/tmp/bincapz1096779990/packages/x86_64/renovate-37.421.6-r0.apk/usr/local/lib/node_modules/renovate/dist/modules/manager/ansible-galaxy/extract.js [🚨 CRITICAL]

RISK KEY DESCRIPTION EVIDENCE
CRITICAL combo/backdoor/remote_eval Executes code from a remote source exec(pack
MEDIUM techniques/code_eval evaluate code dynamically using exec() exec(line))

/tmp/bincapz1096779990/packages/x86_64/renovate-37.421.6-r0.apk/usr/local/lib/node_modules/renovate/node_modules/@yarnpkg/libzip/lib/libzipSync.js [🚨 CRITICAL]

RISK KEY DESCRIPTION EVIDENCE
CRITICAL evasion/base64/php_functions References multiple PHP functions in base64 form N5c3Rlb::$system
ZW1wdH::$empty
c3lzdGVt::$system
zeXN0ZW::$system
MEDIUM data/embedded/base64/terms Contains base64 content FkZHJlc3::$address
RpcmVjdG9ye::$directory
hZGRyZXNz::$address
kaXJlY3Rvcn::$directory
MEDIUM ref/path/relative references and possibly executes relative path ./this
LOW encoding/base64 Supports base64 encoded strings base64

/tmp/bincapz1096779990/packages/x86_64/renovate-37.421.6-r0.apk/usr/local/lib/node_modules/renovate/node_modules/handlebars/dist/cjs/handlebars/compiler/code-gen.js [🚨 CRITICAL]

RISK KEY DESCRIPTION EVIDENCE
CRITICAL evasion/base64/php_functions References multiple PHP functions in base64 form BcnJhe::$Array
FycmF5::$Array
VtcHR5::$empty
ZW1wdH::$empty
lbXB0e::$empty
LOW encoding/base64 Supports base64 encoded strings base64

/tmp/bincapz1096779990/packages/x86_64/renovate-37.421.6-r0.apk/usr/local/lib/node_modules/renovate/node_modules/handlebars/dist/cjs/handlebars/compiler/visitor.js [🚨 CRITICAL]

RISK KEY DESCRIPTION EVIDENCE
CRITICAL evasion/base64/php_functions References multiple PHP functions in base64 form BcnJhe::$Array
FycmF5::$Array
QXJyYX::$Array
ZW1wdH::$empty
LOW encoding/base64 Supports base64 encoded strings base64

/tmp/bincapz1096779990/packages/x86_64/renovate-37.421.6-r0.apk/usr/local/lib/node_modules/renovate/node_modules/source-map/dist/source-map.debug.js [🚨 CRITICAL]

RISK KEY DESCRIPTION EVIDENCE
CRITICAL evasion/base64/php_functions References multiple PHP functions in base64 form BcnJhe::$Array
FycmF5::$Array
NvdW50::$count
QXJyYX::$Array
V4ZW::$exec
ZW1wdH::$empty
jb3Vud::$count
lbXB0e::$empty
zeXN0ZW::$system
HIGH evasion/base64/http base64 HTTP protocol references TW96aWxsYS::$mozilla_slash
MEDIUM data/embedded/base64/terms Contains base64 content VuYW1l::$uname
ZGlyZWN0b3J5::$directory
h0bW::$html
MEDIUM data/embedded/base64/url Contains base64 url aHR0cDovL::$http
aHR0cHM6Ly::$https
h0dHA6Ly::$http
h0dHBzOi8v::$https
odHRwOi8v::$http
odHRwczovL::$https
MEDIUM ref/path/relative references and possibly executes relative path ./foo
LOW encoding/base64 Supports base64 encoded strings base64
LOW encoding/json/decode Decodes JSON messages JSON.parse
LOW encoding/json/encode encodes JSON JSON.stringify
LOW ref/site/url contains embedded HTTPS URLs https://bugzilla.mozilla.org/show_bug.cgi?id=885597.
https://code.google.com/p/closure-compiler/source/browse/trunk/src/com/go
https://docs.google.com/document/d/1U1RGAehQwRypUTovF1KRlpiOFze0b-_2gc6fA
Polymer/polymer-bundler#519
mozilla/source-map#16
mozilla/source-map#30
mozilla/source-map#31

/tmp/bincapz1096779990/packages/x86_64/renovate-37.421.6-r0.apk/usr/local/lib/node_modules/renovate/node_modules/@cdktf/hcl2json/lib/deepmerge.js [🚨 CRITICAL]

RISK KEY DESCRIPTION EVIDENCE
CRITICAL evasion/base64/php_functions References multiple PHP functions in base64 form BcnJhe::$Array
FycmF5::$Array
QXJyYX::$Array
VtcHR5::$empty
LOW encoding/base64 Supports base64 encoded strings base64
LOW encoding/json/encode encodes JSON JSON.stringify

/tmp/bincapz1096779990/packages/x86_64/renovate-37.421.6-r0.apk/usr/local/lib/node_modules/renovate/node_modules/diff/lib/patch/create.js [🚨 CRITICAL]

RISK KEY DESCRIPTION EVIDENCE
CRITICAL evasion/base64/php_functions References multiple PHP functions in base64 form BcnJhe::$Array
FycmF5::$Array
ZW1wdH::$empty
lbXB0e::$empty
MEDIUM data/embedded/base64/url Contains base64 url h0dHBzOi8v::$https
LOW encoding/base64 Supports base64 encoded strings base64
LOW ref/site/url contains embedded HTTPS URLs https://www.artima.com/weblogs/viewpost.jsp?thread=164293

/tmp/bincapz1096779990/packages/x86_64/renovate-37.421.6-r0.apk/usr/local/lib/node_modules/renovate/node_modules/handlebars/dist/amd/handlebars/compiler/compiler.js [🚨 CRITICAL]

RISK KEY DESCRIPTION EVIDENCE
CRITICAL evasion/base64/php_functions References multiple PHP functions in base64 form BcnJhe::$Array
FycmF5::$Array
N5c3Rlb::$system
QXJyYX::$Array
V4ZW::$exec
VtcHR5::$empty
ZW1wdH::$empty
ZXhlY::$exec
lbXB0e::$empty
leGVj::$exec
LOW encoding/base64 Supports base64 encoded strings base64

/tmp/bincapz1096779990/packages/x86_64/renovate-37.421.6-r0.apk/usr/local/lib/node_modules/renovate/node_modules/handlebars/dist/amd/handlebars/compiler/javascript-compiler.js [🚨 CRITICAL]

RISK KEY DESCRIPTION EVIDENCE
CRITICAL evasion/base64/php_functions References multiple PHP functions in base64 form BcnJhe::$Array
NvdW50::$count
QXJyYX::$Array
VtcHR5::$empty
ZXhlY::$exec
lbXB0e::$empty
LOW encoding/base64 Supports base64 encoded strings base64
LOW encoding/json/encode encodes JSON JSON.stringify

/tmp/bincapz1096779990/packages/x86_64/renovate-37.421.6-r0.apk/usr/local/lib/node_modules/renovate/node_modules/handlebars/dist/handlebars.amd.js [🚨 CRITICAL]

RISK KEY DESCRIPTION EVIDENCE
CRITICAL evasion/base64/php_functions References multiple PHP functions in base64 form BcnJhe::$Array
FycmF5::$Array
N5c3Rlb::$system
NvdW50::$count
QXJyYX::$Array
V4ZW::$exec
VtcHR5::$empty
ZW1wdH::$empty
ZXhlY::$exec
lbXB0e::$empty
leGVj::$exec
MEDIUM data/embedded/base64/terms Contains base64 content odG1s::$html
MEDIUM data/embedded/base64/url Contains base64 url h0dHBzOi8v::$https
odHRwczovL::$https
MEDIUM techniques/code_eval evaluate code dynamically using exec() exec(body
LOW encoding/base64 Supports base64 encoded strings base64
LOW encoding/json/encode encodes JSON JSON.stringify
LOW ref/site/url contains embedded HTTPS URLs https://github.com/bestiejs/lodash/blob/master/LICENSE.txt
handlebars-lang/handlebars.js#1639
zaach/jison#291
https://handlebarsjs.com/api-reference/runtime-options.html
https://mathiasbynens.be/notes/globalthis

/tmp/bincapz1096779990/packages/x86_64/renovate-37.421.6-r0.apk/usr/local/lib/node_modules/renovate/node_modules/prettier/index.mjs [🚨 CRITICAL]

RISK KEY DESCRIPTION EVIDENCE
CRITICAL combo/backdoor/remote_eval Executes code from a remote source exec(pack
MEDIUM databases/mysql accesses MySQL databases mysql
MEDIUM kernel/platform get system identification process.platform
process.versions
MEDIUM ref/words/exclamation gets very excited return !!
LOW encoding/base64 Supports base64 encoded strings base64
LOW encoding/json/decode Decodes JSON messages JSON.parse
LOW encoding/json/encode encodes JSON JSON.stringify
LOW env/TERM Look up or override terminal settings TERM
LOW env/get Retrieve environment variable values env.COLORTERM
env.FORCE
env.IGNORE
env.NODE
env.PRETTIER
env.TEAMCITY
env.TERM
env.TEST
LOW fd/read reads from a file handle _reader.read()
provider.read()
LOW fd/write writes to a file handle stream.write(i)
LOW fs/file/stat access filesystem metadata fs.stat(entry.path
fs.stat(path13
fs.statSync(entry.path)
fs.statSync(path13)
LOW fs/file/write writes to file writeFile
LOW net/hostname/resolve resolve network host name to IP address cannot resolve
LOW ref/path/hidden possible hidden file path /app/.heroku
LOW ref/site/url contains embedded HTTPS URLs https://git-scm.com/docs/gitignore/2.22.1
https://github.com/editorconfig/editorconfig-core-js/issues
https://github.com/jedmao/
https://prettier.io/docs/en/plugins.html
LOW ref/words/plugin references a 'plugin' Add a plugin
Multiple plugins can be
Please update your plugin
async function importPlugin
await importPlugin2
await loadPlugin2
const loadPlugin2
const parserPlugin
const pluginDefaults
const printerPlugin
function loadBuiltinPlugins
function loadPlugins
function withPlugins
getSupportInfoWithoutPlugins
plugin2
plugins_default
plugins_proxy_exports
prettierPlugins
return plugin
t find plugin for AST
typeof plugin

/tmp/bincapz1096779990/packages/x86_64/renovate-37.421.6-r0.apk/usr/local/lib/node_modules/renovate/node_modules/diff/lib/patch/parse.js [🚨 CRITICAL]

RISK KEY DESCRIPTION EVIDENCE
CRITICAL evasion/base64/php_functions References multiple PHP functions in base64 form NvdW50::$count
V4ZW::$exec
VtcHR5::$empty
Y291bn::$count
ZXhlY::$exec
leGVj::$exec
MEDIUM data/embedded/base64/url Contains base64 url aHR0cHM6Ly::$https
MEDIUM techniques/code_eval evaluate code dynamically using exec() exec(diffstr
exec(line)
LOW encoding/base64 Supports base64 encoded strings base64
LOW encoding/json/encode encodes JSON JSON.stringify
LOW ref/site/url contains embedded HTTPS URLs https://www.artima.com/weblogs/viewpost.jsp?thread=164293

/tmp/bincapz1096779990/packages/x86_64/renovate-37.421.6-r0.apk/usr/local/lib/node_modules/renovate/node_modules/handlebars/dist/amd/handlebars/helpers/each.js [🚨 CRITICAL]

RISK KEY DESCRIPTION EVIDENCE
CRITICAL evasion/base64/php_functions References multiple PHP functions in base64 form BcnJhe::$Array
QXJyYX::$Array
V4ZW::$exec
ZXhlY::$exec
leGVj::$exec
LOW encoding/base64 Supports base64 encoded strings base64

/tmp/bincapz1096779990/packages/x86_64/renovate-37.421.6-r0.apk/usr/local/lib/node_modules/renovate/node_modules/handlebars/dist/amd/handlebars/runtime.js [🚨 CRITICAL]

RISK KEY DESCRIPTION EVIDENCE
CRITICAL evasion/base64/php_functions References multiple PHP functions in base64 form VtcHR5::$empty
ZXhlY::$exec
leGVj::$exec
MEDIUM ref/path/relative references and possibly executes relative path ./base
./exception
./helpers
./internal
./utils
LOW encoding/base64 Supports base64 encoded strings base64

/tmp/bincapz1096779990/packages/x86_64/renovate-37.421.6-r0.apk/usr/local/lib/node_modules/renovate/node_modules/handlebars/dist/cjs/handlebars/runtime.js [🚨 CRITICAL]

RISK KEY DESCRIPTION EVIDENCE
CRITICAL evasion/base64/php_functions References multiple PHP functions in base64 form V4ZW::$exec
ZXhlY::$exec
lbXB0e::$empty
MEDIUM ref/path/relative references and possibly executes relative path ./base
./exception
./helpers
./internal
./utils
LOW encoding/base64 Supports base64 encoded strings base64

/tmp/bincapz1096779990/packages/x86_64/renovate-37.421.6-r0.apk/usr/local/lib/node_modules/renovate/node_modules/@yarnpkg/libzip/lib/libzipAsync.js [🚨 CRITICAL]

RISK KEY DESCRIPTION EVIDENCE
CRITICAL evasion/base64/php_functions References multiple PHP functions in base64 form N5c3Rlb::$system
ZW1wdH::$empty
c3lzdGVt::$system
zeXN0ZW::$system
MEDIUM data/embedded/base64/terms Contains base64 content FkZHJlc3::$address
RpcmVjdG9ye::$directory
hZGRyZXNz::$address
kaXJlY3Rvcn::$directory
MEDIUM ref/path/relative references and possibly executes relative path ./this
LOW encoding/base64 Supports base64 encoded strings base64

/tmp/bincapz1096779990/packages/x86_64/renovate-37.421.6-r0.apk/usr/local/lib/node_modules/renovate/node_modules/diff/lib/diff/json.js [🚨 CRITICAL]

RISK KEY DESCRIPTION EVIDENCE
CRITICAL evasion/base64/php_functions References multiple PHP functions in base64 form BcnJhe::$Array
FycmF5::$Array
jb3Vud::$count
MEDIUM ref/path/relative references and possibly executes relative path ./base
./line
LOW encoding/base64 Supports base64 encoded strings base64
LOW encoding/json/encode encodes JSON JSON.stringify

/tmp/bincapz1096779990/packages/x86_64/renovate-37.421.6-r0.apk/usr/local/lib/node_modules/renovate/node_modules/handlebars/dist/cjs/handlebars/compiler/javascript-compiler.js [🚨 CRITICAL]

RISK KEY DESCRIPTION EVIDENCE
CRITICAL evasion/base64/php_functions References multiple PHP functions in base64 form BcnJhe::$Array
NvdW50::$count
QXJyYX::$Array
VtcHR5::$empty
ZXhlY::$exec
lbXB0e::$empty
LOW encoding/base64 Supports base64 encoded strings base64
LOW encoding/json/encode encodes JSON JSON.stringify

/tmp/bincapz1096779990/packages/x86_64/renovate-37.421.6-r0.apk/usr/local/lib/node_modules/renovate/node_modules/handlebars/dist/cjs/handlebars/helpers/each.js [🚨 CRITICAL]

RISK KEY DESCRIPTION EVIDENCE
CRITICAL evasion/base64/php_functions References multiple PHP functions in base64 form FycmF5::$Array
QXJyYX::$Array
V4ZW::$exec
ZXhlY::$exec
leGVj::$exec
LOW encoding/base64 Supports base64 encoded strings base64

/tmp/bincapz1096779990/packages/x86_64/renovate-37.421.6-r0.apk/usr/local/lib/node_modules/renovate/node_modules/@breejs/later/lib/index.js [🚨 CRITICAL]

RISK KEY DESCRIPTION EVIDENCE
CRITICAL evasion/base64/php_functions References multiple PHP functions in base64 form BcnJhe::$Array
FycmF5::$Array
NvdW50::$count
QXJyYX::$Array
V4ZW::$exec
Y291bn::$count
ZW1wdH::$empty
ZXhlY::$exec
c3lzdGVt::$system
jb3Vud::$count
MEDIUM data/embedded/base64/url Contains base64 url aHR0cHM6Ly::$https
MEDIUM techniques/code_eval evaluate code dynamically using exec() exec(string
LOW encoding/base64 Supports base64 encoded strings base64
LOW ref/site/url contains embedded HTTPS URLs bunkat/later#188

/tmp/bincapz1096779990/packages/x86_64/renovate-37.421.6-r0.apk/usr/local/lib/node_modules/renovate/node_modules/diff/lib/patch/merge.js [🚨 CRITICAL]

RISK KEY DESCRIPTION EVIDENCE
CRITICAL evasion/base64/php_functions References multiple PHP functions in base64 form FycmF5::$Array
NvdW50::$count
MEDIUM data/embedded/base64/terms Contains base64 content NlbGVjd::$select
c2VsZWN0::$select
zZWxlY3::$select
LOW encoding/base64 Supports base64 encoded strings base64

/tmp/bincapz1096779990/packages/x86_64/renovate-37.421.6-r0.apk/usr/local/lib/node_modules/renovate/node_modules/handlebars/dist/amd/handlebars/compiler/code-gen.js [🚨 CRITICAL]

RISK KEY DESCRIPTION EVIDENCE
CRITICAL evasion/base64/php_functions References multiple PHP functions in base64 form FycmF5::$Array
QXJyYX::$Array
VtcHR5::$empty
lbXB0e::$empty
LOW encoding/base64 Supports base64 encoded strings base64

/tmp/bincapz1096779990/packages/x86_64/renovate-37.421.6-r0.apk/usr/local/lib/node_modules/renovate/node_modules/handlebars/dist/amd/handlebars/compiler/visitor.js [🚨 CRITICAL]

RISK KEY DESCRIPTION EVIDENCE
CRITICAL evasion/base64/php_functions References multiple PHP functions in base64 form BcnJhe::$Array
FycmF5::$Array
lbXB0e::$empty
LOW encoding/base64 Supports base64 encoded strings base64

/tmp/bincapz1096779990/packages/x86_64/renovate-37.421.6-r0.apk/usr/local/lib/node_modules/renovate/node_modules/handlebars/dist/handlebars.runtime.amd.js [🚨 CRITICAL]

RISK KEY DESCRIPTION EVIDENCE
CRITICAL evasion/base64/php_functions References multiple PHP functions in base64 form BcnJhe::$Array
FycmF5::$Array
N5c3Rlb::$system
QXJyYX::$Array
V4ZW::$exec
VtcHR5::$empty
ZW1wdH::$empty
ZXhlY::$exec
leGVj::$exec
MEDIUM data/embedded/base64/terms Contains base64 content odG1s::$html
MEDIUM data/embedded/base64/url Contains base64 url h0dHBzOi8v::$https
odHRwczovL::$https
LOW encoding/base64 Supports base64 encoded strings base64
LOW ref/site/url contains embedded HTTPS URLs https://github.com/bestiejs/lodash/blob/master/LICENSE.txt
handlebars-lang/handlebars.js#1639
https://handlebarsjs.com/api-reference/runtime-options.html
https://mathiasbynens.be/notes/globalthis

/tmp/bincapz1096779990/packages/x86_64/renovate-37.421.6-r0.apk/usr/local/lib/node_modules/renovate/node_modules/diff/lib/diff/base.js [🚨 CRITICAL]

RISK KEY DESCRIPTION EVIDENCE
CRITICAL evasion/base64/php_functions References multiple PHP functions in base64 form FycmF5::$Array
NvdW50::$count
V4ZW::$exec
VtcHR5::$empty
Y291bn::$count
ZXhlY::$exec
leGVj::$exec
MEDIUM data/embedded/base64/terms Contains base64 content c2VsZWN0::$select
LOW encoding/base64 Supports base64 encoded strings base64

/tmp/bincapz1096779990/packages/x86_64/renovate-37.421.6-r0.apk/usr/local/lib/node_modules/renovate/node_modules/handlebars/dist/amd/handlebars/utils.js [🚨 CRITICAL]

RISK KEY DESCRIPTION EVIDENCE
CRITICAL evasion/base64/php_functions References multiple PHP functions in base64 form BcnJhe::$Array
FycmF5::$Array
QXJyYX::$Array
VtcHR5::$empty
MEDIUM data/embedded/base64/url Contains base64 url h0dHBzOi8v::$https
LOW encoding/base64 Supports base64 encoded strings base64
LOW ref/site/url contains embedded HTTPS URLs https://github.com/bestiejs/lodash/blob/master/LICENSE.txt

/tmp/bincapz1096779990/packages/x86_64/renovate-37.421.6-r0.apk/usr/local/lib/node_modules/renovate/node_modules/handlebars/dist/cjs/handlebars/compiler/compiler.js [🚨 CRITICAL]

RISK KEY DESCRIPTION EVIDENCE
CRITICAL evasion/base64/php_functions References multiple PHP functions in base64 form BcnJhe::$Array
FycmF5::$Array
QXJyYX::$Array
V4ZW::$exec
VtcHR5::$empty
ZW1wdH::$empty
ZXhlY::$exec
leGVj::$exec
zeXN0ZW::$system
LOW encoding/base64 Supports base64 encoded strings base64

@octo-sts octo-sts bot closed this Jul 1, 2024
Copy link
Contributor Author

octo-sts bot commented Jul 1, 2024

superseded by #22960

@octo-sts octo-sts bot deleted the wolfictl-30afd2e0-c694-460a-a5a0-af30dd9f4e29 branch July 2, 2024 00:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant