Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2024-21538 & CVE-2024-21538 #1458

Open
matthew2564 opened this issue Nov 7, 2024 · 0 comments
Open

CVE-2024-21538 & CVE-2024-21538 #1458

matthew2564 opened this issue Nov 7, 2024 · 0 comments
Labels
type: question Questions about the usage of the library.

Comments

@matthew2564
Copy link

High & Medium severity vulnerability reported by Snyk

Issues with no direct upgrade or patch:
  ✗ Cross-site Scripting (XSS) [Medium Severity][https://security.snyk.io/vuln/SNYK-JS-COOKIE-8163060] in [email protected]
    introduced by [email protected] > [email protected]
  This issue was fixed in versions: 0.7.0

  ✗ Regular Expression Denial of Service (ReDoS) [High Severity][https://security.snyk.io/vuln/SNYK-JS-CROSSSPAWN-8303230] in [email protected]
    introduced by [email protected] > [email protected] > [email protected] > [email protected]
  This issue was fixed in versions: 7.0.5

Can a new version please be published with upgrades for these both?

Thanks.

@matthew2564 matthew2564 added the type: question Questions about the usage of the library. label Nov 7, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
type: question Questions about the usage of the library.
Development

No branches or pull requests

1 participant