Skip to content

[DepShield] (CVSS 7.5) Vulnerability due to usage of postcss:7.0.36 #7

@sonatype-depshield

Description

@sonatype-depshield

Vulnerabilities

DepShield reports that this application's usage of postcss:7.0.36 results in the following vulnerability(s):


Occurrences

postcss:7.0.36 is a transitive dependency introduced by the following direct dependency(s):

@nuxt/types:2.15.7
        └─ @types/autoprefixer:9.7.2
              └─ postcss:7.0.36

@nuxtjs/tailwindcss:4.2.1
        └─ postcss-custom-properties:11.0.0
              └─ postcss-values-parser:4.0.0
                    └─ postcss:7.0.36

nuxt:2.15.7
        └─ @nuxt/webpack:2.15.7
              └─ postcss:7.0.36
              └─ css-loader:4.3.0
                    └─ postcss:7.0.36
                    └─ icss-utils:4.1.1
                          └─ postcss:7.0.36
                    └─ postcss-modules-extract-imports:2.0.0
                          └─ postcss:7.0.36
                    └─ postcss-modules-local-by-default:3.0.3
                          └─ postcss:7.0.36
                    └─ postcss-modules-scope:2.2.0
                          └─ postcss:7.0.36
                    └─ postcss-modules-values:3.0.0
                          └─ postcss:7.0.36
              └─ cssnano:4.1.11
                    └─ cssnano-preset-default:4.0.8
                          └─ css-declaration-sorter:4.0.1
                                └─ postcss:7.0.36
                          └─ postcss:7.0.36
                          └─ cssnano-util-raw-cache:4.0.1
                                └─ postcss:7.0.36
                          └─ postcss-calc:7.0.5
                                └─ postcss:7.0.36
                          └─ postcss-colormin:4.0.3
                                └─ postcss:7.0.36
                          └─ postcss-convert-values:4.0.1
                                └─ postcss:7.0.36
                          └─ postcss-discard-comments:4.0.2
                                └─ postcss:7.0.36
                          └─ postcss-discard-duplicates:4.0.2
                                └─ postcss:7.0.36
                          └─ postcss-discard-empty:4.0.1
                                └─ postcss:7.0.36
                          └─ postcss-discard-overridden:4.0.1
                                └─ postcss:7.0.36
                          └─ postcss-merge-longhand:4.0.11
                                └─ postcss:7.0.36
                                └─ stylehacks:4.0.3
                                      └─ postcss:7.0.36
                          └─ postcss-merge-rules:4.0.3
                                └─ postcss:7.0.36
                          └─ postcss-minify-font-values:4.0.2
                                └─ postcss:7.0.36
                          └─ postcss-minify-gradients:4.0.2
                                └─ postcss:7.0.36
                          └─ postcss-minify-params:4.0.2
                                └─ postcss:7.0.36
                          └─ postcss-minify-selectors:4.0.2
                                └─ postcss:7.0.36
                          └─ postcss-normalize-charset:4.0.1
                                └─ postcss:7.0.36
                          └─ postcss-normalize-display-values:4.0.2
                                └─ postcss:7.0.36
                          └─ postcss-normalize-positions:4.0.2
                                └─ postcss:7.0.36
                          └─ postcss-normalize-repeat-style:4.0.2
                                └─ postcss:7.0.36
                          └─ postcss-normalize-string:4.0.2
                                └─ postcss:7.0.36
                          └─ postcss-normalize-timing-functions:4.0.2
                                └─ postcss:7.0.36
                          └─ postcss-normalize-unicode:4.0.1
                                └─ postcss:7.0.36
                          └─ postcss-normalize-url:4.0.1
                                └─ postcss:7.0.36
                          └─ postcss-normalize-whitespace:4.0.2
                                └─ postcss:7.0.36
                          └─ postcss-ordered-values:4.1.2
                                └─ postcss:7.0.36
                          └─ postcss-reduce-initial:4.0.3
                                └─ postcss:7.0.36
                          └─ postcss-reduce-transforms:4.0.2
                                └─ postcss:7.0.36
                          └─ postcss-svgo:4.0.3
                                └─ postcss:7.0.36
                          └─ postcss-unique-selectors:4.0.1
                                └─ postcss:7.0.36
                    └─ postcss:7.0.36
              └─ postcss-import:12.0.1
                    └─ postcss:7.0.36
              └─ postcss-loader:3.0.0
                    └─ postcss:7.0.36
              └─ postcss-preset-env:6.7.0
                    └─ autoprefixer:9.8.6
                          └─ postcss:7.0.36
                    └─ css-blank-pseudo:0.1.4
                          └─ postcss:7.0.36
                    └─ css-has-pseudo:0.10.0
                          └─ postcss:7.0.36
                    └─ css-prefers-color-scheme:3.1.1
                          └─ postcss:7.0.36
                    └─ postcss-attribute-case-insensitive:4.0.2
                          └─ postcss:7.0.36
                    └─ postcss-color-functional-notation:2.0.1
                          └─ postcss:7.0.36
                    └─ postcss-color-gray:5.0.0
                          └─ postcss:7.0.36
                    └─ postcss-color-hex-alpha:5.0.3
                          └─ postcss:7.0.36
                    └─ postcss-color-mod-function:3.0.3
                          └─ postcss:7.0.36
                    └─ postcss-color-rebeccapurple:4.0.1
                          └─ postcss:7.0.36
                    └─ postcss-custom-media:7.0.8
                          └─ postcss:7.0.36
                    └─ postcss-custom-properties:8.0.11
                          └─ postcss:7.0.36
                    └─ postcss-custom-selectors:5.1.2
                          └─ postcss:7.0.36
                    └─ postcss-dir-pseudo-class:5.0.0
                          └─ postcss:7.0.36
                    └─ postcss-double-position-gradients:1.0.0
                          └─ postcss:7.0.36
                    └─ postcss-env-function:2.0.2
                          └─ postcss:7.0.36
                    └─ postcss-focus-visible:4.0.0
                          └─ postcss:7.0.36
                    └─ postcss-focus-within:3.0.0
                          └─ postcss:7.0.36
                    └─ postcss-font-variant:4.0.1
                          └─ postcss:7.0.36
                    └─ postcss-gap-properties:2.0.0
                          └─ postcss:7.0.36
                    └─ postcss-image-set-function:3.0.1
                          └─ postcss:7.0.36
                    └─ postcss-initial:3.0.4
                          └─ postcss:7.0.36
                    └─ postcss-lab-function:2.0.1
                          └─ postcss:7.0.36
                    └─ postcss-logical:3.0.0
                          └─ postcss:7.0.36
                    └─ postcss-media-minmax:4.0.0
                          └─ postcss:7.0.36
                    └─ postcss-nesting:7.0.1
                          └─ postcss:7.0.36
                    └─ postcss-overflow-shorthand:2.0.0
                          └─ postcss:7.0.36
                    └─ postcss-page-break:2.0.0
                          └─ postcss:7.0.36
                    └─ postcss-place:4.0.1
                          └─ postcss:7.0.36
                    └─ postcss:7.0.36
                    └─ postcss-pseudo-class-any-link:6.0.0
                          └─ postcss:7.0.36
                    └─ postcss-replace-overflow-wrap:3.0.0
                          └─ postcss:7.0.36
                    └─ postcss-selector-matches:4.0.0
                          └─ postcss:7.0.36
                    └─ postcss-selector-not:4.0.1
                          └─ postcss:7.0.36
              └─ postcss-url:8.0.0
                    └─ postcss:7.0.36
              └─ vue-loader:15.9.8
                    └─ @vue/component-compiler-utils:3.2.2
                          └─ postcss:7.0.36

This is an automated GitHub Issue created by Sonatype DepShield. Details on managing GitHub Apps, including DepShield, are available for personal and organization accounts. Please submit questions or feedback about DepShield to the Sonatype DepShield Community.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions