Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

check those volnerabilities found by Snyk #2

Open
AlGolden opened this issue Oct 29, 2017 · 1 comment
Open

check those volnerabilities found by Snyk #2

AlGolden opened this issue Oct 29, 2017 · 1 comment
Labels

Comments

@AlGolden
Copy link

https://snyk.io/test/github/springblock/Ethereum

  1. Arbitrary Code Injection
    Vulnerable module: growl
    Introduced through: grunt-mocha-cli@2.1.0

2.Command Injection
Vulnerable module: shelljs
Introduced through: grunt-contrib-jshint@1.1.0
Detailed paths

Introduced through: blockchaininfrastructure@springblock/Ethereum#1267a1b257840e259f7a1c514a3e8656f9e1b2e3 › grunt-contrib-jshint@1.1.0 › jshint@2.9.5 › shelljs@0.3.0

  1. Prototype Override Protection Bypass
    Vulnerable module: qs
    Introduced through: grunt-contrib-watch@1.0.0
    Detailed paths

Introduced through: blockchaininfrastructure@springblock/Ethereum#1267a1b257840e259f7a1c514a3e8656f9e1b2e3 › grunt-contrib-watch@1.0.0 › tiny-lr@0.2.1 › qs@5.1.0
Introduced through: blockchaininfrastructure@springblock/Ethereum#1267a1b257840e259f7a1c514a3e8656f9e1b2e3 › grunt-contrib-watch@1.0.0 › tiny-lr@0.2.1 › body-parser@1.14.2 › qs@5.2.0

@status-open-bounty
Copy link

status-open-bounty commented Nov 1, 2017

Current balance: 0.0 ETH
Contract address: 0x92e5c20ab7173ec10be09e02aab5efec648f7629
QR Code
Network: Testnet (Ropsten)
To claim this bounty sign up at https://testing.openbounty.status.im and make sure to update your Ethereum address in My Payment Details so that the bounty is correctly allocated.
To fund it, send test ETH or test ERC20/ERC223 tokens to the contract address.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

3 participants