express icon indicating copy to clipboard operation
express copied to clipboard

Bump qs to 6.9.7 (CVE-2022-24999)

Open christianblais opened this issue 2 years ago • 3 comments

I'm using 5.x, and it still has a dependency on qs 6.9.6, which is vulnerable to prototype pollution. I see you fixed it on master branch with version 6.11.0, but I wasn't sure if it was compatible with this 5.x branch. In doubt, I only bumped the patch version up to the first patched version.

Here's a diff between qs 6.9.6 and 6.9.7.

christianblais avatar Sep 28 '23 14:09 christianblais

Hello, and thank you for this. Looks like it is against the wrong branch, but I will move it. Should have a update to the beta with this for you.

dougwilson avatar Oct 06 '23 14:10 dougwilson

Did the beta update happen here? I can't find it.

djMax avatar Dec 15 '23 22:12 djMax

Hi, also following along for this update to resolve CVE-2022-24999. any updates here @dougwilson @UlisesGascon? Thanks

mcope-rca avatar Jan 25 '24 13:01 mcope-rca