Enabled WebRTC.
Ylian Saint-Hilaire committed
Oct 11, 2021 at 15:19 UTC
57b1622d2d82e192d42d93ac80dcee7906687a13
3 files changed
+345
-2
audit.txt
new
+343
@@ -0,0 +1,343 @@
1
+# npm audit report
2
+
3
+braces <=2.3.2
4
+Severity: high
5
+Regular Expression Denial of Service in braces - https://github.com/advisories/GHSA-g95f-p29q-9xw4
6
+Depends on vulnerable versions of snapdragon
7
+fix available via `npm audit fix`
8
+node_modules/braces
9
+node_modules/readdirp/node_modules/braces
10
+ micromatch 0.2.0 - 3.1.10
11
+ Depends on vulnerable versions of braces
12
+ Depends on vulnerable versions of parse-glob
13
+ Depends on vulnerable versions of snapdragon
14
+ node_modules/micromatch
15
+ node_modules/readdirp/node_modules/micromatch
16
+ anymatch 1.2.0 - 1.3.2
17
+ Depends on vulnerable versions of micromatch
18
+ node_modules/anymatch
19
+ chokidar 1.0.0-rc1 - 2.1.8
20
+ Depends on vulnerable versions of anymatch
21
+ Depends on vulnerable versions of glob-parent
22
+ node_modules/chokidar
23
+ babel-cli *
24
+ Depends on vulnerable versions of chokidar
25
+ node_modules/babel-cli
26
+ minify-js *
27
+ Depends on vulnerable versions of babel-cli
28
+ Depends on vulnerable versions of utils-igor
29
+ node_modules/dir_cache/node_modules/minify-js
30
+ node_modules/minify-js
31
+ node_modules/utils-igor/node_modules/minify-js
32
+ dir_cache >=1.0.2
33
+ Depends on vulnerable versions of minify-js
34
+ node_modules/dir_cache
35
+ utils-igor >=2.0.0
36
+ Depends on vulnerable versions of minify-js
37
+ node_modules/dir_cache/node_modules/minify-js/node_modules/utils-igor
38
+ node_modules/utils-igor
39
+ readdirp 2.2.0 - 2.2.1
40
+ Depends on vulnerable versions of micromatch
41
+ node_modules/readdirp
42
+
43
+deep-extend <0.5.1
44
+Severity: critical
45
+Prototype Pollution in deep-extend - https://github.com/advisories/GHSA-hr2v-3952-633q
46
+fix available via `npm audit fix`
47
+node_modules/deep-extend
48
+ column-layout >=1.3.0
49
+ Depends on vulnerable versions of command-line-args
50
+ Depends on vulnerable versions of deep-extend
51
+ node_modules/column-layout
52
+ command-line-usage 2.0.0 - 3.0.8
53
+ Depends on vulnerable versions of column-layout
54
+ Depends on vulnerable versions of table-layout
55
+ node_modules/column-layout/node_modules/command-line-usage
56
+ node_modules/command-line-usage
57
+ node_modules/jsdoc-parse/node_modules/command-line-usage
58
+ cli-commands <=0.1.0
59
+ Depends on vulnerable versions of command-line-usage
60
+ node_modules/cli-commands
61
+ usage-stats 0.8.0 - 0.8.6
62
+ Depends on vulnerable versions of cli-commands
63
+ node_modules/usage-stats
64
+ app-usage-stats 0.4.0 - 0.5.0
65
+ Depends on vulnerable versions of usage-stats
66
+ node_modules/app-usage-stats
67
+ jsdoc2md-stats 1.0.6 - 2.0.0
68
+ Depends on vulnerable versions of app-usage-stats
69
+ node_modules/jsdoc2md-stats
70
+ command-line-args 2.1.0 - 2.1.6
71
+ Depends on vulnerable versions of command-line-usage
72
+ node_modules/column-layout/node_modules/command-line-args
73
+ node_modules/jsdoc-parse/node_modules/command-line-args
74
+ jsdoc-parse 0.2.5 - 2.0.0
75
+ Depends on vulnerable versions of command-line-args
76
+ Depends on vulnerable versions of file-set
77
+ Depends on vulnerable versions of jsdoc-api
78
+ node_modules/jsdoc-parse
79
+ jsdoc-to-markdown 0.6.0 - 0.6.4 || 1.3.1 - 2.0.0-alpha.23
80
+ Depends on vulnerable versions of command-line-usage
81
+ Depends on vulnerable versions of dmd
82
+ Depends on vulnerable versions of jsdoc-parse
83
+ node_modules/jsdoc-to-markdown
84
+ grunt-jsdoc-to-markdown 0.5.0 - 0.5.1 || 1.2.0 - 1.2.1
85
+ Depends on vulnerable versions of jsdoc-to-markdown
86
+ node_modules/grunt-jsdoc-to-markdown
87
+ command-line-tool 0.3.0 - 0.6.4
88
+ Depends on vulnerable versions of command-line-usage
89
+ node_modules/command-line-tool
90
+ dmd 0.3.23 - 2.0.1
91
+ Depends on vulnerable versions of command-line-tool
92
+ Depends on vulnerable versions of ddata
93
+ Depends on vulnerable versions of stream-handlebars
94
+ node_modules/dmd
95
+ table-layout <=0.4.0
96
+ Depends on vulnerable versions of deep-extend
97
+ node_modules/table-layout
98
+
99
+glob-parent <5.1.2
100
+Severity: high
101
+Regular expression denial of service - https://github.com/advisories/GHSA-ww39-953v-wcq6
102
+fix available via `npm audit fix`
103
+node_modules/glob-parent
104
+ chokidar 1.0.0-rc1 - 2.1.8
105
+ Depends on vulnerable versions of anymatch
106
+ Depends on vulnerable versions of glob-parent
107
+ node_modules/chokidar
108
+ babel-cli *
109
+ Depends on vulnerable versions of chokidar
110
+ node_modules/babel-cli
111
+ minify-js *
112
+ Depends on vulnerable versions of babel-cli
113
+ Depends on vulnerable versions of utils-igor
114
+ node_modules/dir_cache/node_modules/minify-js
115
+ node_modules/minify-js
116
+ node_modules/utils-igor/node_modules/minify-js
117
+ dir_cache >=1.0.2
118
+ Depends on vulnerable versions of minify-js
119
+ node_modules/dir_cache
120
+ utils-igor >=2.0.0
121
+ Depends on vulnerable versions of minify-js
122
+ node_modules/dir_cache/node_modules/minify-js/node_modules/utils-igor
123
+ node_modules/utils-igor
124
+ glob-base *
125
+ Depends on vulnerable versions of glob-parent
126
+ node_modules/glob-base
127
+ parse-glob >=2.1.0
128
+ Depends on vulnerable versions of glob-base
129
+ node_modules/parse-glob
130
+ micromatch 0.2.0 - 3.1.10
131
+ Depends on vulnerable versions of braces
132
+ Depends on vulnerable versions of parse-glob
133
+ Depends on vulnerable versions of snapdragon
134
+ node_modules/micromatch
135
+ node_modules/readdirp/node_modules/micromatch
136
+ anymatch 1.2.0 - 1.3.2
137
+ Depends on vulnerable versions of micromatch
138
+ node_modules/anymatch
139
+ readdirp 2.2.0 - 2.2.1
140
+ Depends on vulnerable versions of micromatch
141
+ node_modules/readdirp
142
+
143
+handlebars <=4.7.6
144
+Severity: critical
145
+Remote code execution in handlebars when compiling templates - https://github.com/advisories/GHSA-f2jv-r9rf-7988
146
+Prototype Pollution in handlebars - https://github.com/advisories/GHSA-w457-6q6x-cgp9
147
+Cross-Site Scripting in handlebars - https://github.com/advisories/GHSA-9prh-257w-9277
148
+Depends on vulnerable versions of optimist
149
+fix available via `npm audit fix`
150
+node_modules/ddata/node_modules/handlebars
151
+node_modules/stream-handlebars/node_modules/handlebars
152
+ ddata >=0.1.18
153
+ Depends on vulnerable versions of handlebars
154
+ node_modules/ddata
155
+ dmd 0.3.23 - 2.0.1
156
+ Depends on vulnerable versions of command-line-tool
157
+ Depends on vulnerable versions of ddata
158
+ Depends on vulnerable versions of stream-handlebars
159
+ node_modules/dmd
160
+ jsdoc-to-markdown 0.6.0 - 0.6.4 || 1.3.1 - 2.0.0-alpha.23
161
+ Depends on vulnerable versions of command-line-usage
162
+ Depends on vulnerable versions of dmd
163
+ Depends on vulnerable versions of jsdoc-parse
164
+ node_modules/jsdoc-to-markdown
165
+ grunt-jsdoc-to-markdown 0.5.0 - 0.5.1 || 1.2.0 - 1.2.1
166
+ Depends on vulnerable versions of jsdoc-to-markdown
167
+ node_modules/grunt-jsdoc-to-markdown
168
+ stream-handlebars <=0.1.6
169
+ Depends on vulnerable versions of handlebars
170
+ node_modules/stream-handlebars
171
+
172
+minimatch <3.0.2
173
+Severity: high
174
+Regular Expression Denial of Service in minimatch - https://github.com/advisories/GHSA-hxm2-r34f-qmc5
175
+fix available via `npm audit fix`
176
+node_modules/jsdoc-parse/node_modules/minimatch
177
+ glob 3.0.0 - 5.0.14
178
+ Depends on vulnerable versions of minimatch
179
+ node_modules/jsdoc-parse/node_modules/glob
180
+ file-set <=0.2.8
181
+ Depends on vulnerable versions of glob
182
+ node_modules/jsdoc-parse/node_modules/file-set
183
+ jsdoc-parse 0.2.5 - 2.0.0
184
+ Depends on vulnerable versions of command-line-args
185
+ Depends on vulnerable versions of file-set
186
+ Depends on vulnerable versions of jsdoc-api
187
+ node_modules/jsdoc-parse
188
+ jsdoc-to-markdown 0.6.0 - 0.6.4 || 1.3.1 - 2.0.0-alpha.23
189
+ Depends on vulnerable versions of command-line-usage
190
+ Depends on vulnerable versions of dmd
191
+ Depends on vulnerable versions of jsdoc-parse
192
+ node_modules/jsdoc-to-markdown
193
+ grunt-jsdoc-to-markdown 0.5.0 - 0.5.1 || 1.2.0 - 1.2.1
194
+ Depends on vulnerable versions of jsdoc-to-markdown
195
+ node_modules/grunt-jsdoc-to-markdown
196
+
197
+minimist <0.2.1
198
+Severity: moderate
199
+Prototype Pollution in minimist - https://github.com/advisories/GHSA-vh95-rmgr-6w4m
200
+fix available via `npm audit fix`
201
+node_modules/optimist/node_modules/minimist
202
+ optimist >=0.6.0
203
+ Depends on vulnerable versions of minimist
204
+ node_modules/optimist
205
+ handlebars <=4.7.6
206
+ Depends on vulnerable versions of optimist
207
+ node_modules/ddata/node_modules/handlebars
208
+ node_modules/stream-handlebars/node_modules/handlebars
209
+ ddata >=0.1.18
210
+ Depends on vulnerable versions of handlebars
211
+ node_modules/ddata
212
+ dmd 0.3.23 - 2.0.1
213
+ Depends on vulnerable versions of command-line-tool
214
+ Depends on vulnerable versions of ddata
215
+ Depends on vulnerable versions of stream-handlebars
216
+ node_modules/dmd
217
+ jsdoc-to-markdown 0.6.0 - 0.6.4 || 1.3.1 - 2.0.0-alpha.23
218
+ Depends on vulnerable versions of command-line-usage
219
+ Depends on vulnerable versions of dmd
220
+ Depends on vulnerable versions of jsdoc-parse
221
+ node_modules/jsdoc-to-markdown
222
+ grunt-jsdoc-to-markdown 0.5.0 - 0.5.1 || 1.2.0 - 1.2.1
223
+ Depends on vulnerable versions of jsdoc-to-markdown
224
+ node_modules/grunt-jsdoc-to-markdown
225
+ stream-handlebars <=0.1.6
226
+ Depends on vulnerable versions of handlebars
227
+ node_modules/stream-handlebars
228
+ node-windows >=0.1.5
229
+ Depends on vulnerable versions of optimist
230
+ node_modules/node-windows
231
+
232
+nedb *
233
+Severity: high
234
+Prototype Pollution - https://github.com/advisories/GHSA-339j-hqgx-qrrx
235
+Depends on vulnerable versions of binary-search-tree
236
+Depends on vulnerable versions of underscore
237
+No fix available
238
+node_modules/nedb
239
+
240
+set-value <4.0.1
241
+Severity: high
242
+Prototype Pollution in set-value - https://github.com/advisories/GHSA-4jqc-8m5r-9rpr
243
+fix available via `npm audit fix`
244
+node_modules/set-value
245
+ cache-base >=0.7.0
246
+ Depends on vulnerable versions of set-value
247
+ Depends on vulnerable versions of union-value
248
+ node_modules/cache-base
249
+ base >=0.7.0
250
+ Depends on vulnerable versions of cache-base
251
+ node_modules/base
252
+ snapdragon 0.6.0 - 0.10.1
253
+ Depends on vulnerable versions of base
254
+ node_modules/snapdragon
255
+ braces <=2.3.2
256
+ Depends on vulnerable versions of snapdragon
257
+ node_modules/braces
258
+ node_modules/readdirp/node_modules/braces
259
+ micromatch 0.2.0 - 3.1.10
260
+ Depends on vulnerable versions of braces
261
+ Depends on vulnerable versions of parse-glob
262
+ Depends on vulnerable versions of snapdragon
263
+ node_modules/micromatch
264
+ node_modules/readdirp/node_modules/micromatch
265
+ anymatch 1.2.0 - 1.3.2
266
+ Depends on vulnerable versions of micromatch
267
+ node_modules/anymatch
268
+ chokidar 1.0.0-rc1 - 2.1.8
269
+ Depends on vulnerable versions of anymatch
270
+ Depends on vulnerable versions of glob-parent
271
+ node_modules/chokidar
272
+ babel-cli *
273
+ Depends on vulnerable versions of chokidar
274
+ node_modules/babel-cli
275
+ minify-js *
276
+ Depends on vulnerable versions of babel-cli
277
+ Depends on vulnerable versions of utils-igor
278
+ node_modules/dir_cache/node_modules/minify-js
279
+ node_modules/minify-js
280
+ node_modules/utils-igor/node_modules/minify-js
281
+ dir_cache >=1.0.2
282
+ Depends on vulnerable versions of minify-js
283
+ node_modules/dir_cache
284
+ utils-igor >=2.0.0
285
+ Depends on vulnerable versions of minify-js
286
+ node_modules/dir_cache/node_modules/minify-js/node_modules/utils-igor
287
+ node_modules/utils-igor
288
+ readdirp 2.2.0 - 2.2.1
289
+ Depends on vulnerable versions of micromatch
290
+ node_modules/readdirp
291
+ expand-brackets 1.0.0 - 2.1.4
292
+ Depends on vulnerable versions of snapdragon
293
+ node_modules/readdirp/node_modules/expand-brackets
294
+ extglob 1.0.0 - 2.0.4
295
+ Depends on vulnerable versions of snapdragon
296
+ node_modules/readdirp/node_modules/extglob
297
+ nanomatch >=0.1.1
298
+ Depends on vulnerable versions of snapdragon
299
+ node_modules/nanomatch
300
+ union-value *
301
+ Depends on vulnerable versions of set-value
302
+ node_modules/union-value
303
+
304
+underscore 1.3.2 - 1.12.0
305
+Severity: high
306
+Arbitrary Code Execution in underscore - https://github.com/advisories/GHSA-cf4h-3jhx-xvhq
307
+No fix available
308
+node_modules/jsdoc-75lb/node_modules/underscore
309
+node_modules/underscore
310
+ binary-search-tree *
311
+ Depends on vulnerable versions of underscore
312
+ node_modules/binary-search-tree
313
+ nedb *
314
+ Depends on vulnerable versions of binary-search-tree
315
+ Depends on vulnerable versions of underscore
316
+ node_modules/nedb
317
+ jsdoc-75lb *
318
+ Depends on vulnerable versions of underscore
319
+ node_modules/jsdoc-75lb
320
+ jsdoc-api 0.1.0 - 3.0.0
321
+ Depends on vulnerable versions of jsdoc-75lb
322
+ node_modules/jsdoc-api
323
+ jsdoc-parse 0.2.5 - 2.0.0
324
+ Depends on vulnerable versions of command-line-args
325
+ Depends on vulnerable versions of file-set
326
+ Depends on vulnerable versions of jsdoc-api
327
+ node_modules/jsdoc-parse
328
+ jsdoc-to-markdown 0.6.0 - 0.6.4 || 1.3.1 - 2.0.0-alpha.23
329
+ Depends on vulnerable versions of command-line-usage
330
+ Depends on vulnerable versions of dmd
331
+ Depends on vulnerable versions of jsdoc-parse
332
+ node_modules/jsdoc-to-markdown
333
+ grunt-jsdoc-to-markdown 0.5.0 - 0.5.1 || 1.2.0 - 1.2.1
334
+ Depends on vulnerable versions of jsdoc-to-markdown
335
+ node_modules/grunt-jsdoc-to-markdown
336
+
337
+48 vulnerabilities (1 low, 3 moderate, 27 high, 17 critical)
338
+
339
+To address issues that do not require attention, run:
340
+ npm audit fix
341
+
342
+Some issues need review, and may require choosing
343
+a different dependency.
views/default-mobile.handlebars
+1
-1
@@ -1303,7 +1303,7 @@
1303
QV('managePhoneNumber1', (features & 0x02000000) && (features & 0x04000000));
1304
QV('managePhoneNumber2', (features & 0x02000000) && !(features & 0x04000000));
1305
1306
- attemptWebRTC = 0; // For now, default WebRTC off unless we set it in the URL.
1306
+ //attemptWebRTC = false; // For now, default WebRTC off unless we set it in the URL.
1307
if (args.webrtc != null) { attemptWebRTC = (args.webrtc == 1); }
1308
1309
// Session Refresh Timer
views/default.handlebars
+1
-1
@@ -1463,7 +1463,7 @@
1463
if (!args.locale) { var x = getstore('loctag', 0); if ((x != null) && (x != '*')) { args.locale = x; } }
1464
debugmode = args.debug;
1465
1466
- attemptWebRTC = 0; // For now, default WebRTC off unless we set it in the URL.
1466
+ //attemptWebRTC = false; // For now, default WebRTC off unless we set it in the URL.
1467
if (args.webrtc != null) { attemptWebRTC = (args.webrtc == 1); }
1468
1469
QV('p13AutoConnect', debugmode); // Files