Showing 91 of 91 total issues
tough-cookie
Regular Expression Denial of Service Open
Open
"tough-cookie": {
"version": "2.3.2",
"bundled": true,
"dev": true,
"optional": true,
- Read upRead up
- Exclude checks
Regular Expression Denial of Service
Overview:
The tough-cookie module is vulnerable to regular expression denial of service. Input of around 50k characters is required for a slow down of around 2 seconds.
Unless node was compiled using the -DHTTPMAXHEADER_SIZE= option the default header max length is 80kb so the impact of the ReDoS is limited to around 7.3 seconds of blocking.
At the time of writing all version <=2.3.2 are vulnerable
Recommendation:
Please update to version 2.3.3 or greater
debug
Regular Expression Denial of Service Open
Open
"debug": {
"version": "2.6.8",
"bundled": true,
"dev": true,
"optional": true,
- Read upRead up
- Exclude checks
Regular Expression Denial of Service
Overview:
The debug module is vulnerable to regular expression denial of service when untrusted user input is passed into the o
formatter. It takes around 50k characters to block for 2 seconds making this a low severity issue.
Recommendation:
Upgrade to version 2.6.9 or greater if you are on the 2.6.x series or 3.1.0 or greater.
Rule doesn't have all its properties in alphabetical order. Open
Open
#jump_to, #jump_wrapper {
- Exclude checks
2 IDs in the selector, really? Open
Open
#jump_to:hover #jump_wrapper {
- Exclude checks
Don't use IDs in selectors. Open
Open
#jump_page .source {
- Exclude checks
Element (span.lineno) is overqualified, just use .lineno without element name. Open
Open
span.lineno { background-color: #f0f0f0; padding: 0 5px 0 5px; }
- Exclude checks
Unqualified attribute selectors are known to be slow. Open
Open
[hidden] {
- Exclude checks
Don't use IDs in selectors. Open
Open
#jump_to a {
- Exclude checks
Outlines should only be modified using :focus. Open
Open
a:active,
- Exclude checks
The box-sizing property isn't supported in IE6 and IE7. Open
Open
box-sizing: border-box; /* 1 */
- Exclude checks
Rule doesn't have all its properties in alphabetical order. Open
Open
@font-face {
- Exclude checks
Heading (h2) has already been defined. Open
Open
h2 {
- Exclude checks
Missing standard property 'box-shadow' to go along with '-webkit-box-shadow'. Open
Open
-webkit-box-shadow: 0 0 25px #777; -moz-box-shadow: 0 0 25px #777;
- Exclude checks
Don't use IDs in selectors. Open
Open
#jump_wrapper {
- Exclude checks
Rule doesn't have all its properties in alphabetical order. Open
Open
.sections blockquote p {
- Exclude checks
Don't use IDs in selectors. Open
Open
#jump_page {
- Exclude checks
Don't use IDs in selectors. Open
Open
#jump_to, #jump_wrapper {
- Exclude checks
Rule doesn't have all its properties in alphabetical order. Open
Open
hr {
- Exclude checks
Don't use IDs in selectors. Open
Open
#jump_to, #jump_wrapper {
- Exclude checks
Don't use IDs in selectors. Open
Open
#container {
- Exclude checks