Linux v69820.1blu.de 4.15.0 #1 SMP Mon Sep 30 15:36:27 MSK 2024 x86_64
Apache/2.4.58
Server IP : 195.90.215.149 & Your IP : 216.73.217.80
Domains :
Cant Read [ /etc/named.conf ]
User : www-data
Terminal
Auto Root
Create File
Create Folder
Localroot Suggester
Backdoor Destroyer
Readme
/
usr /
share /
nodejs /
@npmcli /
arborist /
lib /
Delete
Unzip
Name
Size
Permission
Date
Action
arborist
[ DIR ]
drwxr-xr-x
2024-07-10 10:56
add-rm-pkg-deps.js
4.89
KB
-rw-r--r--
2023-11-23 07:39
audit-report.js
11.99
KB
-rw-r--r--
2023-11-23 07:39
calc-dep-flags.js
3.07
KB
-rw-r--r--
2023-11-23 07:39
can-place-dep.js
13.94
KB
-rw-r--r--
2023-11-23 07:39
case-insensitive-map.js
1.32
KB
-rw-r--r--
2023-11-23 07:39
consistent-resolve.js
1.29
KB
-rw-r--r--
2023-11-23 07:39
debug.js
1.2
KB
-rw-r--r--
2023-11-23 07:39
deepest-nesting-target.js
691
B
-rw-r--r--
2023-11-23 07:39
dep-valid.js
4.94
KB
-rw-r--r--
2023-11-23 07:39
diff.js
9.57
KB
-rw-r--r--
2023-11-23 07:39
edge.js
6.83
KB
-rw-r--r--
2023-11-23 07:39
from-path.js
1.04
KB
-rw-r--r--
2023-11-23 07:39
gather-dep-set.js
1.26
KB
-rw-r--r--
2023-11-23 07:39
get-workspace-nodes.js
863
B
-rw-r--r--
2023-11-23 07:39
index.js
353
B
-rw-r--r--
2023-11-23 07:39
inventory.js
3.2
KB
-rw-r--r--
2023-11-23 07:39
link.js
3
KB
-rw-r--r--
2023-11-23 07:39
node.js
43.21
KB
-rw-r--r--
2023-11-23 07:39
optional-set.js
1.32
KB
-rw-r--r--
2023-11-23 07:39
override-resolves.js
230
B
-rw-r--r--
2023-11-23 07:39
override-set.js
2.42
KB
-rw-r--r--
2023-11-23 07:39
peer-entry-sets.js
2.57
KB
-rw-r--r--
2023-11-23 07:39
place-dep.js
19.7
KB
-rw-r--r--
2023-11-23 07:39
printable.js
5.09
KB
-rw-r--r--
2023-11-23 07:39
query-selector-all.js
26.17
KB
-rw-r--r--
2023-11-23 07:39
realpath.js
2.58
KB
-rw-r--r--
2023-11-23 07:39
relpath.js
131
B
-rw-r--r--
2023-11-23 07:39
reset-dep-flags.js
638
B
-rw-r--r--
2023-11-23 07:39
retire-path.js
491
B
-rw-r--r--
2023-11-23 07:39
shrinkwrap.js
36.6
KB
-rw-r--r--
2023-11-23 07:39
signal-handling.js
2.19
KB
-rw-r--r--
2023-11-23 07:39
signals.js
1.35
KB
-rw-r--r--
2023-11-23 07:39
spec-from-lock.js
874
B
-rw-r--r--
2023-11-23 07:39
tracker.js
3.29
KB
-rw-r--r--
2023-11-23 07:39
tree-check.js
4.02
KB
-rw-r--r--
2023-11-23 07:39
version-from-tgz.js
1.45
KB
-rw-r--r--
2023-11-23 07:39
vuln.js
5.93
KB
-rw-r--r--
2023-11-23 07:39
yarn-lock.js
10.58
KB
-rw-r--r--
2023-11-23 07:39
Save
Rename
// An object representing a vulnerability either as the result of an // advisory or due to the package in question depending exclusively on // vulnerable versions of a dep. // // - name: package name // - range: Set of vulnerable versions // - nodes: Set of nodes affected // - effects: Set of vulns triggered by this one // - advisories: Set of advisories (including metavulns) causing this vuln. // All of the entries in via are vulnerability objects returned by // @npmcli/metavuln-calculator // - via: dependency vulns which cause this one const { satisfies, simplifyRange } = require('semver') const semverOpt = { loose: true, includePrerelease: true } const localeCompare = require('@isaacs/string-locale-compare')('en') const npa = require('npm-package-arg') const _range = Symbol('_range') const _simpleRange = Symbol('_simpleRange') const _fixAvailable = Symbol('_fixAvailable') const severities = new Map([ ['info', 0], ['low', 1], ['moderate', 2], ['high', 3], ['critical', 4], [null, -1], ]) for (const [name, val] of severities.entries()) { severities.set(val, name) } class Vuln { constructor ({ name, advisory }) { this.name = name this.via = new Set() this.advisories = new Set() this.severity = null this.effects = new Set() this.topNodes = new Set() this[_range] = null this[_simpleRange] = null this.nodes = new Set() // assume a fix is available unless it hits a top node // that locks it in place, setting this false or {isSemVerMajor, version}. this[_fixAvailable] = true this.addAdvisory(advisory) this.packument = advisory.packument this.versions = advisory.versions } get fixAvailable () { return this[_fixAvailable] } set fixAvailable (f) { this[_fixAvailable] = f // if there's a fix available for this at the top level, it means that // it will also fix the vulns that led to it being there. to get there, // we set the vias to the most "strict" of fix availables. // - false: no fix is available // - {name, version, isSemVerMajor} fix requires -f, is semver major // - {name, version} fix requires -f, not semver major // - true: fix does not require -f // TODO: duped entries may require different fixes but the current // structure does not support this, so the case were a top level fix // corrects a duped entry may mean you have to run fix more than once for (const v of this.via) { // don't blow up on loops if (v.fixAvailable === f) { continue } if (f === false) { v.fixAvailable = f } else if (v.fixAvailable === true) { v.fixAvailable = f } else if (typeof f === 'object' && ( typeof v.fixAvailable !== 'object' || !v.fixAvailable.isSemVerMajor)) { v.fixAvailable = f } } } get isDirect () { for (const node of this.nodes.values()) { for (const edge of node.edgesIn) { if (edge.from.isProjectRoot || edge.from.isWorkspace) { return true } } } return false } testSpec (spec) { const specObj = npa(spec) if (!specObj.registry) { return true } if (specObj.subSpec) { spec = specObj.subSpec.rawSpec } for (const v of this.versions) { if (satisfies(v, spec) && !satisfies(v, this.range, semverOpt)) { return false } } return true } toJSON () { return { name: this.name, severity: this.severity, isDirect: this.isDirect, // just loop over the advisories, since via is only Vuln objects, // and calculated advisories have all the info we need via: [...this.advisories].map(v => v.type === 'metavuln' ? v.dependency : { ...v, versions: undefined, vulnerableVersions: undefined, id: undefined, }).sort((a, b) => localeCompare(String(a.source || a), String(b.source || b))), effects: [...this.effects].map(v => v.name).sort(localeCompare), range: this.simpleRange, nodes: [...this.nodes].map(n => n.location).sort(localeCompare), fixAvailable: this[_fixAvailable], } } addVia (v) { this.via.add(v) v.effects.add(this) // call the setter since we might add vias _after_ setting fixAvailable this.fixAvailable = this.fixAvailable } deleteVia (v) { this.via.delete(v) v.effects.delete(this) } deleteAdvisory (advisory) { this.advisories.delete(advisory) // make sure we have the max severity of all the vulns causing this one this.severity = null this[_range] = null this[_simpleRange] = null // refresh severity for (const advisory of this.advisories) { this.addAdvisory(advisory) } // remove any effects that are no longer relevant const vias = new Set([...this.advisories].map(a => a.dependency)) for (const via of this.via) { if (!vias.has(via.name)) { this.deleteVia(via) } } } addAdvisory (advisory) { this.advisories.add(advisory) const sev = severities.get(advisory.severity) this[_range] = null this[_simpleRange] = null if (sev > severities.get(this.severity)) { this.severity = advisory.severity } } get range () { return this[_range] || (this[_range] = [...this.advisories].map(v => v.range).join(' || ')) } get simpleRange () { if (this[_simpleRange] && this[_simpleRange] === this[_range]) { return this[_simpleRange] } const versions = [...this.advisories][0].versions const range = this.range const simple = simplifyRange(versions, range, semverOpt) return this[_simpleRange] = this[_range] = simple } isVulnerable (node) { if (this.nodes.has(node)) { return true } const { version } = node.package if (!version) { return false } for (const v of this.advisories) { if (v.testVersion(version)) { this.nodes.add(node) return true } } return false } } module.exports = Vuln