chore(bot): update v3dist from kse-console-embed:kse-release-4.1 to kubesphere/console:master at 2024-12-19 17:32:19+0800 #4368
29 new alerts including 8 critical severity security vulnerabilities
New alerts in code changed by this pull request
Security Alerts:
- 8 critical
- 19 high
- 2 medium
Alerts not introduced by this pull request might have been detected because the code changes were too large.
See annotations below for details.
Annotations
Check warning on line 85 in packages/bootstrap/assets/v3dist/0.e2c230924a693caf0aca.js
Code scanning / CodeQL
Prototype-polluting assignment Medium
.
Check warning on line 85 in packages/bootstrap/assets/v3dist/0.e2c230924a693caf0aca.js
Code scanning / CodeQL
Prototype-polluting assignment Medium
.
Check failure on line 300 in packages/bootstrap/assets/v3dist/00280aae09f2a71c1ab46c7cfb9f491c.js
Code scanning / CodeQL
Useless regular-expression character escape High
.
Check warning on line 184 in packages/bootstrap/assets/v3dist/0c125a87d8efb9ce303b6b91783eb165.js
Code scanning / CodeQL
Overly permissive regular expression range Medium
Check failure on line 238 in packages/bootstrap/assets/v3dist/0cbaf3ecc6b20dbc83c2164e9a1eac02.js
Code scanning / CodeQL
Bad HTML filtering regexp High
Check failure on line 1 in packages/bootstrap/assets/v3dist/1.7a352d6cdc028e26eafc.js
Code scanning / CodeQL
Incomplete URL substring sanitization High
' can be anywhere in the URL, and arbitrary hosts may come before or after it.
Check failure on line 1 in packages/bootstrap/assets/v3dist/1.7a352d6cdc028e26eafc.js
Code scanning / CodeQL
Incomplete URL substring sanitization High
' can be anywhere in the URL, and arbitrary hosts may come before or after it.
Check failure on line 5141 in packages/bootstrap/assets/v3dist/117389396b5ae8131c2a299bfc802c7a.js
Code scanning / CodeQL
Incomplete string escaping or encoding High
Check failure on line 206 in packages/bootstrap/assets/v3dist/2fe13737434324ed67582ac97d484c54.js
Code scanning / CodeQL
Unsafe dynamic method access Critical
, which may allow remote code execution.
Check failure on line 214 in packages/bootstrap/assets/v3dist/2fe13737434324ed67582ac97d484c54.js
Code scanning / CodeQL
Unvalidated dynamic method call High
name may dispatch to unexpected target and cause an exception.
Check failure on line 1 in packages/bootstrap/assets/v3dist/3.6c9dc306377f46d55ef0.js
Code scanning / CodeQL
Hard-coded credentials Critical
.
Check failure on line 1 in packages/bootstrap/assets/v3dist/3.6c9dc306377f46d55ef0.js
Code scanning / CodeQL
Incomplete regular expression for hostnames High
Check failure on line 1 in packages/bootstrap/assets/v3dist/3.6c9dc306377f46d55ef0.js
Code scanning / CodeQL
Incomplete regular expression for hostnames High
Check failure on line 168 in packages/bootstrap/assets/v3dist/642f5bce034554539cc93a5b965e730a.js
Code scanning / CodeQL
Bad HTML filtering regexp High
Check failure on line 206 in packages/bootstrap/assets/v3dist/6f61a36cc8b4cd9472559c6f0c2374a0.js
Code scanning / CodeQL
Unsafe dynamic method access Critical
, which may allow remote code execution.
Check failure on line 214 in packages/bootstrap/assets/v3dist/6f61a36cc8b4cd9472559c6f0c2374a0.js
Code scanning / CodeQL
Unvalidated dynamic method call High
name may dispatch to unexpected target and cause an exception.
Check warning on line 1925 in packages/bootstrap/assets/v3dist/806bfd960245b1da40a7e1057a076289.js
Code scanning / CodeQL
Overly permissive regular expression range Medium
Check warning on line 1925 in packages/bootstrap/assets/v3dist/806bfd960245b1da40a7e1057a076289.js
Code scanning / CodeQL
Overly permissive regular expression range Medium
Check warning on line 1925 in packages/bootstrap/assets/v3dist/806bfd960245b1da40a7e1057a076289.js
Code scanning / CodeQL
Overly permissive regular expression range Medium
Check failure on line 206 in packages/bootstrap/assets/v3dist/89392e9dbbec39477b4b3e52a0676422.js
Code scanning / CodeQL
Unsafe dynamic method access Critical
, which may allow remote code execution.
Check failure on line 214 in packages/bootstrap/assets/v3dist/89392e9dbbec39477b4b3e52a0676422.js
Code scanning / CodeQL
Unvalidated dynamic method call High
name may dispatch to unexpected target and cause an exception.
Check failure on line 206 in packages/bootstrap/assets/v3dist/908119c25a234151c8c7c1a97005c866.js
Code scanning / CodeQL
Unsafe dynamic method access Critical
, which may allow remote code execution.
Check failure on line 214 in packages/bootstrap/assets/v3dist/908119c25a234151c8c7c1a97005c866.js
Code scanning / CodeQL
Unvalidated dynamic method call High
name may dispatch to unexpected target and cause an exception.
Check failure on line 206 in packages/bootstrap/assets/v3dist/99f6bcba35fb277563c6362f3caab715.js
Code scanning / CodeQL
Unsafe dynamic method access Critical
, which may allow remote code execution.
Check failure on line 214 in packages/bootstrap/assets/v3dist/99f6bcba35fb277563c6362f3caab715.js
Code scanning / CodeQL
Unvalidated dynamic method call High
name may dispatch to unexpected target and cause an exception.