Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Prototype Pollution security vulnerability #179

Closed
tomsoal opened this issue Nov 17, 2021 · 2 comments · Fixed by #180
Closed

Prototype Pollution security vulnerability #179

tomsoal opened this issue Nov 17, 2021 · 2 comments · Fixed by #180

Comments

@tomsoal
Copy link
Contributor

tomsoal commented Nov 17, 2021

https://www.whitesourcesoftware.com/vulnerability-database/CVE-2019-10744

This module pulls in [email protected] which pulls in a vulnerable version of lodash.template

Need to move to [email protected] which will resolve this issue.

@simonua
Copy link
Collaborator

simonua commented Nov 17, 2021

Hi @tomsoal, I don't know whether @miickel is still involved in this repo. A few years ago I took over some of the improvements and package publishing, but I have since moved on myself.

It may be easiest if you fork and update.

@tomsoal
Copy link
Contributor Author

tomsoal commented Nov 17, 2021

Hi @simonua thanks for the advice, have raised the PR for this here #180

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants