Research Article

A Server-Side JavaScript Security Architecture for Secure Integration of Third-Party Libraries

Table 5


Package Vulnerability Category

hapi-auth-jwt2Authentication Bypass
momentRegular Expression Denial of Service
i18n-node-angularDenial of Service
i18n-node-angularContent Injection
hawkRegular Expression Denial of Service
is-my-json-validRegular Expression Denial of Service
mqtt-packetDenial of Service
mapbox.jsContent Injection
jshamcrestRegular Expression Denial of Service
jadedownRegular Expression Denial of Service
bittorrent-dhtRemote Memory Disclosure
wsRemote Memory Disclosure
mysqlSQL Injection
hapiRoute level CORS config
ecstaticDenial of Service
hapiDenial of Service
mustacheContent Injection
handlebarsContent Injection
keystoneAuthentication Weakness
millisecondsRegular Expression Denial of Service
tarSymlink Arbitrary File Overwrite
sendRoot Path Disclosure
gmCommand Injection
ansi2htmlRegular Expression Denial of Service
uglify-jsRegular Expression Denial of Service
secure-compareInsecure Comparison
mapbox.jsContent Injection via TileJSON attribute
bleachRegular Expression Denial of Service
msRegular Expression Denial of Service
hapiIncorrect handling of CORS preflight request headers
ldapauthLDAP Injection
datatablesCross-Site Scripting
ldapauth-forkLDAP Injection
ulgify-jsIncorrect non-boolean comparisons
ungitCommand injection
geddyDirectory traversal
semverRegular Expression Denial of Service
jsonwebtokenVerification Bypass
markedRegular Expression Denial of Service
markedVBScript Content Injection
sequelizeSQL Injection in Order
serve-staticOpen Redirect
serve-indexXSS
inertHidden Directories Always Served
fancy-serverDirectory Traversal
dns-syncCommand Injection
bassmasterJavaScript Execution in Bassmaster
crumbCORS Token Disclosure
expressNo Charset In Content-Type Header
hapiFile Descriptor Leak Can Cause DoS Vulnerability
hapiRosetta-flash Jsonp Vulnerability
libyamlHeap-based Buffer Overflow When Parsing YAML Tags
markedMultiple Content Injection Vulnerabilities
nhoustonDirectory Traversal
paypal-ipnValidation Bypass
printerPotential Command Injection on Untrusted Input
qsDenial-of-Service Extended Event Loop Blocking
qsDenial-of-Service Memory Exhaustion
remarkableContent Injection
sendDirectory Traversal
stDirectory Traversal
syntax-errorPotential For Script Injection
validatorisURL Regular Expression Denial of Service
validatorXSS Filter Bypass via Encoded URL
yarDenial-of-Service
js-yamlDeserialization Code Execution
hubot-scriptsScripts Potential Command Injection in Email.coffee
tomatoAPI Admin Auth Weakness
codem-transcodePotential Command Injection in Ffprobe Functionality
ep_imageconvertUnauthenticated Remote Command Injection
libnotifyCommand Injection in Libnotify.notify
connectMiddleware Reflected Cross-Site Scripting
validatorXSS Filter Bypasses