-
-
Notifications
You must be signed in to change notification settings - Fork 27k
Security Issue Flagged by Snyk #10698
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Comments
See https://snyk.io/vuln/SNYK-JS-SSRI-1085630 This issue is a duplicate of #10699 |
Note that the first comment is a dump of multiple security reports and the second only describes 1 and refers to another GH Issue about that 1 security issue. Issue #10699 is only a partial duplicate of #10698 (this Issue). Linkifying the SNYK security reports:
|
Thanks, I've noticed I accidently copied [email protected] into the message, this section should not be there. |
@gregorymey-dev This issue needs to be reopened as there is no other issue covering the |
Indeed. This still needs to be fixed. We need to upgrade
|
Any updates on this issue? I see this issue is still closed
|
Hi Guys, Was out of circulation for a while, IO would want to re-open this case. |
None of these issues affect how CRA uses these dependencies. There is nothing to address here. |
Hi Guys,
Thanks for the awesome tool.
Could you investigate the vulnerabilities that Snyk flagged.
✗ Arbitrary Code Injection [Medium Severity][https://snyk.io/vuln/SNYK-JS-EJS-1049328] in [email protected]
introduced by [email protected] > [email protected] > [email protected] > @surma/[email protected] > [email protected]
This issue was fixed in versions: 3.1.6
✗ Regular Expression Denial of Service (ReDoS) [Medium Severity][https://snyk.io/vuln/SNYK-JS-GLOBPARENT-1016905] in [email protected]
introduced by [email protected] > [email protected] > [email protected] > [email protected] > [email protected] > [email protected]
This issue was fixed in versions: 5.1.2
✗ Regular Expression Denial of Service (ReDoS) [Medium Severity][https://snyk.io/vuln/SNYK-JS-HTMLPARSESTRINGIFY2-1079307] in [email protected]
introduced by [email protected] > [email protected]
No upgrade or patch available
✗ Regular Expression Denial of Service (ReDoS) [Medium Severity][https://snyk.io/vuln/SNYK-JS-ISSVG-1085627] in [email protected]
introduced by [email protected] > [email protected] > [email protected] > [email protected] > [email protected] > [email protected]
This issue was fixed in versions: 4.2.2
✗ Regular Expression Denial of Service (ReDoS) [High Severity][https://snyk.io/vuln/SNYK-JS-SSRI-1085630] in [email protected]
introduced by [email protected] > [email protected] > [email protected] > [email protected] > [email protected]
This issue was fixed in versions: 8.0.1
The text was updated successfully, but these errors were encountered: