SEC-957 [listenbrainz-server] CVE-2022-38900: decode-uri-component <= 0.2.0
SEC-909 [listenbrainz-server] CVE-2022-37601: loader-utils < 1.4.1
SEC-908 [listenbrainz-server] CVE-2022-2421: socket.io-parser >= 4.0.0, < 4.0.5
SEC-902 [listenbrainz-server] CVE-2022-37601: loader-utils < 2.0.3
SEC-896 [listenbrainz-server] CVE-2022-2421: socket.io-parser < 4.0.5
SEC-890 [listenbrainz-server] GHSA-36jr-mh4h-2g58: d3-color < 3.1.0
SEC-808 [listenbrainz-server] CVE-2022-25858: terser >= 5.0.0, < 5.14.2
SEC-798 [troi-recommendation-playground] CVE-2022-31117: ujson < 5.4.0
SEC-797 [troi-recommendation-playground] CVE-2022-31116: ujson < 5.4.0
SEC-796 [troi-recommendation-playground] CVE-2022-31116: ujson < 5.4.0
SEC-795 [troi-recommendation-playground] CVE-2022-31117: ujson < 5.4.0
SEC-794 [listenbrainz-server] CVE-2022-31117: ujson < 5.4.0
SEC-793 [listenbrainz-server] CVE-2022-31116: ujson < 5.4.0
SEC-792 [listenbrainz-server] CVE-2022-31117: ujson < 5.4.0
SEC-791 [listenbrainz-server] CVE-2022-31116: ujson < 5.4.0
SEC-788 [listenbrainz-server] CVE-2022-31116: ujson < 5.4.0
SEC-787 [listenbrainz-server] CVE-2022-31117: ujson < 5.4.0
SEC-783 [listenbrainz-server] CVE-2021-23382: postcss < 7.0.36
SEC-782 [listenbrainz-server] CVE-2021-20066: jsdom <= 16.4.0
SEC-749 [troi-recommendation-playground] CVE-2021-45958: ujson >= 1.34, < 5.2.0
SEC-748 [troi-recommendation-playground] CVE-2021-45958: ujson >= 1.34, < 5.2.0
SEC-747 [listenbrainz-server] CVE-2021-45958: ujson >= 1.34, < 5.2.0
SEC-746 [listenbrainz-server] CVE-2021-45958: ujson >= 1.34, < 5.2.0
SEC-744 [listenbrainz-server] CVE-2021-45958: ujson >= 1.34, < 5.2.0
SEC-717 [listenbrainz-server] CVE-2022-1365: cross-fetch < 3.1.5
SEC-714 [listenbrainz-server] CVE-2021-3807: ansi-regex >= 4.0.0, < 4.1.1
SEC-713 [listenbrainz-server] CVE-2021-3807: ansi-regex >= 5.0.0, < 5.0.1
SEC-702 [listenbrainz-server] CVE-2021-44906: minimist < 1.2.6
SEC-684 [listenbrainz-server] CVE-2021-44906: minimist <= 1.2.5
SEC-678 [listenbrainz-server] CVE-2021-23648: @braintree/sanitize-url < 6.0.0
SEC-640 [listenbrainz-server] GHSA-wxhq-pm8v-cw75: clean-css < 4.1.11
SEC-635 [listenbrainz-server] CVE-2020-7793: ua-parser-js < 0.7.23
SEC-573 [listenbrainz-server] CVE-2022-0235: node-fetch < 2.6.7
SEC-538 [listenbrainz-server] CVE-2021-33430: numpy >= 1.9.0, < 1.21
SEC-500 [listenbrainz-server] CVE-2020-7789: node-notifier < 8.0.1
SEC-499 [listenbrainz-server] CVE-2021-3807: ansi-regex > 2.1.1, < 5.0.1
SEC-498 [listenbrainz-server] CVE-2021-3803: nth-check < 2.0.1
SEC-497 [listenbrainz-server] CVE-2021-3918: json-schema < 0.4.0
SEC-496 [listenbrainz-server] CVE-2021-3777: tmpl < 1.0.5
SEC-495 [listenbrainz-server] CVE-2020-15168: node-fetch < 2.6.1
SEC-494 [listenbrainz-server] CVE-2020-7733: ua-parser-js < 0.7.22
SEC-493 [listenbrainz-server] CVE-2021-23343: path-parse < 1.0.7
SEC-492 [listenbrainz-server] CVE-2020-28469: glob-parent < 5.1.2
SEC-491 [listenbrainz-server] CVE-2021-23362: hosted-git-info < 2.8.9
SEC-490 [listenbrainz-server] CVE-2021-27292: ua-parser-js >= 0.7.14, < 0.7.24
SEC-466 [listenbrainz-server] CVE-2021-3803: nth-check < 2.0.1
SEC-464 [listenbrainz-server] CVE-2021-3777: tmpl < 1.0.5
SEC-462 [listenbrainz-server] CVE-2021-3807: ansi-regex < 6.0.1
SEC-451 [listenbrainz-server] CVE-2021-23440: set-value < 4.0.1
SEC-428 [listenbrainz-server] CVE-2021-23343: path-parse < 1.0.7
Type:
Task
Resolution:
Fixed
Priority:
Normal
GitHub Alert ID:
3,157,608,042
CVE-2022-38900 affects package decode-uri-component <= 0.2.0 which metabrainz/listenbrainz-server depends on.
Please self-assign this ticket and check metabrainz/listenbrainz-server alerts , then:
Dismiss the corresponding alert in GitHub if there is a valid reason (patch in progress, no bandwidth, tolerable risk, inaccurate alert, or unused code) for.
Create a new ticket in the affected JIRA project, link it to this ticket (do not move this ticket to another project), and address that new ticket.
In both case, GitHub Bot will close this ticket for you, except if you backport a patch on a vulnerable dependency.
This ticket has been created by SEC automation.
{"searchers":{"groups":[{"searchers":[{"name":"Project","id":"project","key":"issue.field.project","isShown":true,"lastViewed":1742280725848},{"name":"Summary","id":"summary","key":"issue.field.summary","isShown":true},{"name":"Type","id":"issuetype","key":"issue.field.issuetype","isShown":true,"lastViewed":1742280725851},{"name":"Status","id":"status","key":"issue.field.status","isShown":true,"lastViewed":1742280725860},{"name":"Priority","id":"priority","key":"issue.field.priority","isShown":true},{"name":"Resolution","id":"resolution","key":"issue.field.resolution","isShown":true},{"name":"Creator","id":"creator","key":"issue.field.creator","isShown":true},{"name":"Affects Version","id":"version","key":"issue.field.affectsversions","isShown":false},{"name":"Fix Version","id":"fixfor","key":"issue.field.fixversions","isShown":false},{"name":"Component","id":"component","key":"issue.field.components","isShown":true,"lastViewed":1742280725865},{"name":"% Limits","id":"workratio","key":"issue.field.workratio","isShown":true},{"name":"Link types","id":"issue_link_type","key":"issue.field.issuelinks","isShown":true},{"name":"Environment","id":"environment","key":"issue.field.environment","isShown":true},{"name":"Description","id":"description","key":"issue.field.description","isShown":true},{"name":"Comment","id":"comment","key":"issue.field.comment","isShown":true},{"name":"Label","id":"labels","key":"issue.field.labels","isShown":true},{"name":"Query","id":"text","key":"text","isShown":true},{"name":"Development","id":"customfield_10310","key":"com.atlassian.jira.plugins.jira-development-integration-plugin:devsummary","isShown":true},{"name":"Epic Color","id":"customfield_10015","key":"com.pyxis.greenhopper.jira:gh-epic-color","isShown":false},{"name":"Epic Link","id":"customfield_10012","key":"com.pyxis.greenhopper.jira:gh-epic-link","isShown":true},{"name":"Epic Name","id":"customfield_10014","key":"com.pyxis.greenhopper.jira:gh-epic-label","isShown":true},{"name":"Epic Status","id":"customfield_10013","key":"com.pyxis.greenhopper.jira:gh-epic-status","isShown":false},{"name":"Flagged","id":"customfield_10210","key":"com.atlassian.jira.plugin.system.customfieldtypes:multicheckboxes","isShown":true},{"name":"GitHub Alert ID","id":"customfield_10410","key":"com.atlassian.jira.plugin.system.customfieldtypes:float","isShown":true},{"name":"Original story points","id":"customfield_10514","key":"com.atlassian.jpo:jpo-custom-field-original-story-points","isShown":true},{"name":"Parent Link","id":"customfield_10511","key":"com.atlassian.jpo:jpo-custom-field-parent","isShown":false},{"name":"Rank","id":"customfield_10010","key":"com.pyxis.greenhopper.jira:gh-lexo-rank","isShown":true},{"name":"Size Estimate","id":"customfield_10000","key":"com.atlassian.jira.plugin.system.customfieldtypes:select","isShown":true},{"name":"Sprint","id":"customfield_10011","key":"com.pyxis.greenhopper.jira:gh-sprint","isShown":true},{"name":"Story Points","id":"customfield_10110","key":"com.atlassian.jira.plugin.system.customfieldtypes:float","isShown":false},{"name":"Team","id":"customfield_10510","key":"com.atlassian.teams:rm-teams-custom-field-team","isShown":true}],"type":"DETAILS","title":"Details"},{"searchers":[{"name":"Created Date","id":"created","key":"issue.field.created","isShown":true},{"name":"Updated Date","id":"updated","key":"issue.field.updated","isShown":true},{"name":"Resolution Date","id":"resolutiondate","key":"issue.field.resolution.date","isShown":true},{"name":"Due Date","id":"duedate","key":"issue.field.duedate","isShown":true},{"name":"Target end","id":"customfield_10513","key":"com.atlassian.jpo:jpo-custom-field-baseline-end","isShown":true},{"name":"Target start","id":"customfield_10512","key":"com.atlassian.jpo:jpo-custom-field-baseline-start","isShown":true}],"type":"DATES","title":"Dates"},{"searchers":[{"name":"Assignee","id":"assignee","key":"issue.field.assignee","isShown":true,"lastViewed":1742280725863},{"name":"Reporter","id":"reporter","key":"issue.field.reporter","isShown":true}],"type":"PEOPLE","title":"People"}]},"values":{"issuetype":{"name":"Type","editHtml":"\n\n\n\n <div class=\"field-group aui-field-issuetype\" >\n <label for=\"searcher-type\">Type</label> <select class=\"select js-default-checkboxmultiselect\"\n id=\"searcher-type\"\n multiple=\"multiple\"\n name=\"type\"\n data-max-inline-results-displayed=\"100\"\n data-placeholder-text=\"Find Issue Types...\">\n <optgroup>\n \n <option class=\" \"\n id=\"type_-2\"\n title=\"All Standard Issue Types\"\n value=\"-2\">All Standard Issue Types</option>\n \n <option class=\" \"\n id=\"type_-3\"\n title=\"All Sub-Task Issue Types\"\n value=\"-3\">All Sub-Task Issue Types</option>\n </optgroup>\n\n <optgroup label=\"Standard Issue Types\">\n \n <option class=\" imagebacked 10520 \"\n data-icon=\"/secure/viewavatar?size=xsmall&avatarId=10308&avatarType=issuetype\"\n data-fallback-icon=\"/images/icons/issuetypes/blank.png\"\n id=\"type_3\"\n title=\"Task\"\n value=\"3\">Task</option>\n </optgroup>\n\n <optgroup label=\"Sub-Task Issue Types\">\n \n <option class=\" imagebacked 10520 \"\n data-icon=\"/secure/viewavatar?size=xsmall&avatarId=10306&avatarType=issuetype\"\n data-fallback-icon=\"/images/icons/issuetypes/blank.png\"\n id=\"type_5\"\n title=\"Sub-task\"\n value=\"5\">Sub-task</option>\n </optgroup>\n </select>\n </div>\n ","validSearcher":true,"isShown":true},"component":{"name":"Component","viewHtml":" <div class=\"searcherValue\">\n \n <label class=\"fieldLabel\" for=\"fieldcomponent\">Component:</label><span id=\"fieldcomponent\" class=\"fieldValue\">\n \n LB </span></div>\n","editHtml":"\n <div class=\"field-group aui-field-projectconstant\" >\n <label for=\"searcher-component\">Component</label> <select class=\"select js-default-checkboxmultiselectcomponent\"\n id=\"searcher-component\"\n multiple=\"multiple\"\n name=\"component\"\n data-max-inline-results-displayed=\"100\"\n aria-label=\"Search for components\">\n <optgroup label=\"\">\n <option value=\"-1\" title=\"No Component\">No Component</option>\n <option value=\"id:AB\" title=\"AB\">AB</option>\n <option value=\"id:BB\" title=\"BB\">BB</option>\n <option value=\"id:BU\" title=\"BU\">BU</option>\n <option value=\"id:CAA\" title=\"CAA\">CAA</option>\n <option value=\"id:CB\" title=\"CB\">CB</option>\n <option value=\"id:DS\" title=\"DS\">DS</option>\n <option value=\"id:IRC\" title=\"IRC\">IRC</option>\n <option selected=\"selected\" value=\"id:LB\" title=\"LB\">LB</option>\n <option value=\"id:MBS\" title=\"MBS\">MBS</option>\n <option value=\"id:MEBDH\" title=\"MEBDH\">MEBDH</option>\n <option value=\"id:MEBW\" title=\"MEBW\">MEBW</option>\n <option value=\"id:PW\" title=\"PW\">PW</option>\n <option value=\"id:SEARCH\" title=\"SEARCH\">SEARCH</option>\n <option value=\"id:SIR\" title=\"SIR\">SIR</option>\n </optgroup>\n </select>\n </div>\n \n","jql":"component = LB","validSearcher":true,"isShown":true},"project":{"name":"Project","viewHtml":" <div class=\"searcherValue\">\n \n <label class=\"fieldLabel\" for=\"fieldpid\">Project:</label><span id=\"fieldpid\" class=\"fieldValue\">\n \n <a data-pid=\"10430\" data-issue-type-ids=\"\" href=\"/browse/SEC\" title=\"Browse MetaBrainz Sec Management project\">MetaBrainz Sec Management</a> </span></div>\n","editHtml":" \n <div class=\"field-group aui-field-project\" >\n <label for=\"searcher-pid\">Project</label> <select class=\"js-project-checkboxmultiselect\"\n data-placeholder-text=\"Find Projects...\"\n id=\"searcher-pid\"\n multiple=\"multiple\"\n name=\"pid\">\n <optgroup label=\"Recent Projects\">\n <option data-icon=\"/secure/projectavatar?pid=10060&size=small\"\n title=\"CritiqueBrainz\"\n value=\"10060\">\n CritiqueBrainz (CB)\n </option>\n <option data-icon=\"/secure/projectavatar?pid=10080&size=small\"\n title=\"Zapped: AcousticBrainz\"\n value=\"10080\">\n Zapped: AcousticBrainz (AB)\n </option>\n </optgroup>\n <optgroup label=\"All Projects\" >\n <option data-icon=\"/secure/projectavatar?pid=10430&size=small\"\n selected=\"selected\" title=\"MetaBrainz Sec Management\"\n value=\"10430\">\n MetaBrainz Sec Management (SEC)\n </option>\n \n <option data-icon=\"/secure/projectavatar?pid=10072&size=small\"\n title=\"Area Requests\"\n value=\"10072\">\n Area Requests (AREQ)\n </option>\n <option data-icon=\"/secure/projectavatar?pid=10043&size=small\"\n title=\"BookBrainz\"\n value=\"10043\">\n BookBrainz (BB)\n </option>\n <option data-icon=\"/secure/projectavatar?pid=10121&size=small\"\n title=\"BrainzUtils\"\n value=\"10121\">\n BrainzUtils (BU)\n </option>\n <option data-icon=\"/secure/projectavatar?pid=10044&size=small\"\n title=\"Image Archives\"\n value=\"10044\">\n Image Archives (IMG)\n </option>\n <option data-icon=\"/secure/projectavatar?pid=10070&size=small\"\n title=\"Instrument Requests\"\n value=\"10070\">\n Instrument Requests (INST)\n </option>\n <option data-icon=\"/secure/projectavatar?pid=10046&size=small\"\n title=\"libcoverart\"\n value=\"10046\">\n libcoverart (LCA)\n </option>\n <option data-icon=\"/secure/projectavatar?pid=10041&size=small\"\n title=\"libdiscid\"\n value=\"10041\">\n libdiscid (LIB)\n </option>\n <option data-icon=\"/secure/projectavatar?pid=10040&size=small\"\n title=\"libmusicbrainz\"\n value=\"10040\">\n libmusicbrainz (LMB)\n </option>\n <option data-icon=\"/secure/projectavatar?pid=10431&size=small\"\n title=\"LinkedBrainz\"\n value=\"10431\">\n LinkedBrainz (LINKB)\n </option>\n <option data-icon=\"/secure/projectavatar?pid=10101&size=small\"\n title=\"ListenBrainz\"\n value=\"10101\">\n ListenBrainz (LB)\n </option>\n <option data-icon=\"/secure/projectavatar?pid=10130&size=small\"\n title=\"MBSpotify\"\n value=\"10130\">\n MBSpotify (MSP)\n </option>\n <option data-icon=\"/secure/projectavatar?pid=10100&size=small\"\n title=\"MetaBrainz\"\n value=\"10100\">\n MetaBrainz (MEB)\n </option>\n <option data-icon=\"/secure/projectavatar?pid=10021&size=small\"\n title=\"MetaBrainz Hosting\"\n value=\"10021\">\n MetaBrainz Hosting (MBH)\n </option>\n <option data-icon=\"/secure/projectavatar?pid=10031&size=small\"\n title=\"Mobile Applications\"\n value=\"10031\">\n Mobile Applications (MOBILE)\n </option>\n <option data-icon=\"/secure/projectavatar?pid=10630&size=small\"\n title=\"MusicBrainz Batch Edits\"\n value=\"10630\">\n MusicBrainz Batch Edits (MBBE)\n </option>\n <option data-icon=\"/secure/projectavatar?pid=10020&size=small\"\n title=\"MusicBrainz Search Server\"\n value=\"10020\">\n MusicBrainz Search Server (SEARCH)\n </option>\n <option data-icon=\"/secure/projectavatar?pid=10000&size=small\"\n title=\"MusicBrainz Server\"\n value=\"10000\">\n MusicBrainz Server (MBS)\n </option>\n <option data-icon=\"/secure/projectavatar?pid=10032&size=small\"\n title=\"MusicBrainz Style\"\n value=\"10032\">\n MusicBrainz Style (STYLE)\n </option>\n <option data-icon=\"/secure/projectavatar?pid=10045&size=small\"\n title=\"MusicBrainz Virtual Machines\"\n value=\"10045\">\n MusicBrainz Virtual Machines (MBVM)\n </option>\n <option data-icon=\"/secure/projectavatar?pid=10230&size=small\"\n title=\"Organisation\"\n value=\"10230\">\n Organisation (ORG)\n </option>\n <option data-icon=\"/secure/projectavatar?pid=10022&size=small\"\n title=\"Other\"\n value=\"10022\">\n Other (OTHER)\n </option>\n <option data-icon=\"/secure/projectavatar?pid=10042&size=small\"\n title=\"Picard\"\n value=\"10042\">\n Picard (PICARD)\n </option>\n <option data-icon=\"/secure/projectavatar?pid=10071&size=small\"\n title=\"Picard Website\"\n value=\"10071\">\n Picard Website (PW)\n </option>\n <option data-icon=\"/secure/projectavatar?pid=10330&size=small\"\n title=\"SpamBrainz\"\n value=\"10330\">\n SpamBrainz (SPAM)\n </option>\n <option data-icon=\"/secure/projectavatar?pid=10047&size=small\"\n title=\"Zapped: FreeDB Gateway\"\n value=\"10047\">\n Zapped: FreeDB Gateway (FREEDB)\n </option>\n <option data-icon=\"/secure/projectavatar?pid=10050&size=small\"\n title=\"Zapped: Geordi\"\n value=\"10050\">\n Zapped: Geordi (GEORDI)\n </option>\n </optgroup>\n </select>\n </div>\n \n\n","jql":"project = SEC","validSearcher":true,"isShown":true},"assignee":{"name":"Assignee","editHtml":"\n \n <div class=\"field-group aui-field-userlist\" >\n <label for=\"searcher-assigneeSelect\">Assignee</label> <fieldset rel=\"assignee\" class=\"hidden user-group-searcher-params\">\n </fieldset>\n <select class=\"js-usergroup-checkboxmultiselect\" multiple=\"multiple\" id=\"assignee\" name=\"assignee\" data-placeholder-text=\"Enter username or group\">\n <optgroup>\n <option class=\"headerOption\" data-icon=\"https://tickets.metabrainz.org/secure/useravatar?size=xsmall&avatarId=10213\" value=\"empty\" title=\"Unassigned\">Unassigned</option>\n </optgroup>\n <optgroup>\n </optgroup>\n </select>\n <input type=\"hidden\" name=\"check_prev_assignee\" value=\"true\">\n </div>\n \n","validSearcher":true,"isShown":true},"status":{"name":"Status","editHtml":"\n <div class=\"field-group aui-field-constants\" >\n <label for=\"searcher-status\">Status</label> <select class=\"select js-default-checkboxmultiselectstatuslozenge\"\n data-placeholder-text=\"Find Statuses...\"\n id=\"searcher-status\"\n multiple=\"multiple\"\n name=\"status\"\n data-max-inline-results-displayed=\"100\"\n data-footer-text=\"-91 more options. Continue typing to refine further.\" data-status-lozenge=\"true\">\n <optgroup >\n <option class=\"imagebacked\" data-icon=\"/images/icons/statuses/open.png\" value=\"1\" title=\"Open\" data-simple-status=\"{"id":"1","name":"Open","description":"The issue is open and ready for the assignee to start work on it.","iconUrl":"/images/icons/statuses/open.png","statusCategory":{"id":2,"key":"new","colorName":"default"}}\">Open</option>\n <option class=\"imagebacked\" data-icon=\"/images/icons/statuses/inprogress.png\" value=\"3\" title=\"In Progress\" data-simple-status=\"{"id":"3","name":"In Progress","description":"This issue is being actively worked on at the moment by the assignee.","iconUrl":"/images/icons/statuses/inprogress.png","statusCategory":{"id":4,"key":"indeterminate","colorName":"inprogress"}}\">In Progress</option>\n <option class=\"imagebacked\" data-icon=\"/images/icons/statuses/reopened.png\" value=\"4\" title=\"Reopened\" data-simple-status=\"{"id":"4","name":"Reopened","description":"This issue was once resolved, but the resolution was deemed incorrect. From here issues are either marked assigned or resolved.","iconUrl":"/images/icons/statuses/reopened.png","statusCategory":{"id":2,"key":"new","colorName":"default"}}\">Reopened</option>\n <option class=\"imagebacked\" data-icon=\"/images/icons/statuses/resolved.png\" value=\"5\" title=\"Review Submitted\" data-simple-status=\"{"id":"5","name":"Review Submitted","description":"A review has been submitted and is waiting peer review before the issue can be closed.","iconUrl":"/images/icons/statuses/resolved.png","statusCategory":{"id":4,"key":"indeterminate","colorName":"inprogress"}}\">Review Submitted</option>\n <option class=\"imagebacked\" data-icon=\"/images/icons/statuses/closed.png\" value=\"6\" title=\"Closed\" data-simple-status=\"{"id":"6","name":"Closed","description":"The issue is considered finished, the resolution is correct. Issues which are closed can be reopened.","iconUrl":"/images/icons/statuses/closed.png","statusCategory":{"id":3,"key":"done","colorName":"success"}}\">Closed</option>\n <option class=\"imagebacked\" data-icon=\"/images/icons/statuses/needinfo.png\" value=\"10005\" title=\"Blocked\" data-simple-status=\"{"id":"10005","name":"Blocked","description":"Progress cannot continue on the issue until another ticket is resolved.","iconUrl":"/images/icons/statuses/needinfo.png","statusCategory":{"id":2,"key":"new","colorName":"default"}}\">Blocked</option>\n <option class=\"imagebacked\" data-icon=\"/images/icons/status_generic.gif\" value=\"10111\" title=\"Rejected\" data-simple-status=\"{"id":"10111","name":"Rejected","description":"","iconUrl":"/images/icons/status_generic.gif","statusCategory":{"id":3,"key":"done","colorName":"success"}}\">Rejected</option>\n <option class=\"imagebacked\" data-icon=\"/images/icons/statuses/generic.png\" value=\"10208\" title=\"Mockup Required\" data-simple-status=\"{"id":"10208","name":"Mockup Required","description":"This ticket needs a mockup to progress.","iconUrl":"/images/icons/statuses/generic.png","statusCategory":{"id":2,"key":"new","colorName":"default"}}\">Mockup Required</option>\n <option class=\"imagebacked\" data-icon=\"/images/icons/statuses/generic.png\" value=\"10209\" title=\"Mockup Submitted\" data-simple-status=\"{"id":"10209","name":"Mockup Submitted","description":"A mockup has been submitted, pending review.","iconUrl":"/images/icons/statuses/generic.png","statusCategory":{"id":4,"key":"indeterminate","colorName":"inprogress"}}\">Mockup Submitted</option>\n </optgroup>\n</select>\n </div>\n \n","validSearcher":true,"isShown":true}}}
[{"id":-1,"name":"My open issues","jql":"assignee = currentUser() AND resolution = Unresolved order by updated DESC","isSystem":true,"sharePermissions":[],"requiresLogin":true},{"id":-2,"name":"Reported by me","jql":"reporter = currentUser() order by created DESC","isSystem":true,"sharePermissions":[],"requiresLogin":true},{"id":-4,"name":"All issues","jql":"order by created DESC","isSystem":true,"sharePermissions":[],"requiresLogin":false},{"id":-5,"name":"Open issues","jql":"resolution = Unresolved order by priority DESC,updated DESC","isSystem":true,"sharePermissions":[],"requiresLogin":false},{"id":-9,"name":"Done issues","jql":"statusCategory = Done order by updated DESC","isSystem":true,"sharePermissions":[],"requiresLogin":false},{"id":-3,"name":"Viewed recently","jql":"issuekey in issueHistory() order by lastViewed DESC","isSystem":true,"sharePermissions":[],"requiresLogin":false},{"id":-6,"name":"Created recently","jql":"created >= -1w order by created DESC","isSystem":true,"sharePermissions":[],"requiresLogin":false},{"id":-7,"name":"Resolved recently","jql":"resolutiondate >= -1w order by updated DESC","isSystem":true,"sharePermissions":[],"requiresLogin":false},{"id":-8,"name":"Updated recently","jql":"updated >= -1w order by updated DESC","isSystem":true,"sharePermissions":[],"requiresLogin":false}]
0.3
0
It has been automatically marked as resolved in GitHub, but this has not been propagated to this SEC ticket for some reason.
References:
I also checked that the listenbrainz-server repository does not currently depends on any vulnerable version of decode-uri-component node module.
P.S. By checking indirect dependencies, I found out that listenbrainz-server currently depends on the deprecated source-map-resolve node module.