Closed
Description
Is this a bug report?
no
Can you also reproduce the problem with npm 4.x?
Yes
Environment
Irrelevant
Actual Behavior
There is a vulnerability identified by NSP in the version of url-loader currently set as a dependency.
"react-scripts@1.0.14 > url-loader@0.5.9 > mime@1.3.6 "
url-loader has fixed this issue since 0.6.
Metadata
Metadata
Assignees
Type
Projects
Relationships
Development
No branches or pull requests
Activity
Timer commentedon Oct 5, 2017
I'll accept a PR for this but there's no rush because it's for untrusted user input (& simply a DoS).
Update url-loader to 0.6.2 for mime ReDoS vuln (facebook#3246)
Update url-loader to 0.6.2 for mime ReDoS vuln (facebook#3246)