october/october

Licenses: (LGPL-3.0 OR MIT) | Unknown | MIT

License

>=v1.0.319, <v1.1.11;
>=v4.0.0, <v4.1.17;
>=v1.1.11, <v1.1.12;
>=v2.0.0, <v4.0.0;
>=v4.1.17;
MIT>=v1.1.12, <v2.0.0;

Direct Vulnerabilities

Known vulnerabilities in the october/october package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • L
Incorrect Authorization

>=0.0.0
  • M
Incorrect Authorization

>=0.0.0
  • H
Incomplete List of Disallowed Inputs

>=0.0.0
  • L
Cross-site Scripting (XSS)

>=0.0.0
  • M
Protection Mechanism Failure

<3.7.13>=4.0.0, <4.1.5
  • M
Arbitrary Code Injection

<3.7.14>=4.0.0, <4.1.10
  • M
Cross-site Scripting (XSS)

<3.7.14>=4.0.0, <4.1.10
  • M
Cross-site Scripting (XSS)

<3.7.14>=4.0.0, <4.1.10
  • M
Cross-site Scripting (XSS)

<3.7.14>=4.0.0, <4.1.10
  • H
Cross-site Scripting (XSS)

<3.7.13>=4.0.0, <4.0.12
  • M
Arbitrary File Upload

<3.7.10
  • M
Cross-site Scripting (XSS)

>=0.0.0
  • M
URL Redirection to Untrusted Site ('Open Redirect')

>=3.2.0, <3.6.0
  • H
Cross-site Scripting (XSS)

>=0.0.0
  • M
Cross-site Scripting (XSS)

>=3.0.0, <3.5.2
  • M
Cross-site Scripting (XSS)

>=0.0.0
  • M
Cross-site Scripting (XSS)

<1.0.319
  • M
Cross-site Scripting (XSS)

>=0.0.0
  • M
Arbitrary Code Injection

<3.0.74
  • M
Access Restriction Bypass

<2.1.12
  • M
Remote Code Execution (RCE)

>=1.0.469, <1.0.470>=1.1.0, <1.1.1
  • M
Cross-site Scripting (XSS)

>=1.0.319, <1.0.469
  • L
Privilege Escalation

>=1.0.319, <1.0.470
  • M
Remote Code Execution (RCE)

>=1.0.319, <1.0.469
  • M
Arbitrary File Read

>=1.0.421, <1.0.469
  • M
Cross-site Scripting (XSS)

<1.0.426
  • H
Cross-site Scripting (XSS)

>=1.0.319, <1.0.466
  • H
Cross-site Scripting (XSS)

>=1.0.319, <1.0.467
  • M
Arbitrary File Read

>=1.0.319, <1.0.466
  • H
Cross-site Scripting (XSS)

>=1.0.319, <1.0.466
  • M
Arbitrary File Upload

>=1.0.319, <1.0.466
  • M
Arbitrary File Write

>=1.0.319, <1.0.466
  • M
Command Injection

>=1.0.319, <1.0.466
  • H
Arbitrary Code Execution

<1.0.437
  • M
Cross-site Scripting (XSS)

<1.0.437
  • C
File Path Modification

<1.0.413
  • C
Arbitrary Code Execution

<1.0.413
  • H
Arbitrary Code Injection

<1.0.413
  • M
Cross-site Scripting (XSS)

<1.0.413
  • H
Arbitrary Code Execution

<1.0.413
  • H
Cross-site Request Forgery (CSRF)

<1.0.427
  • M
Cross-site Scripting (XSS)

<1.0.431
  • C
Configuration Modification

=1.0.412