tortilla
tortilla copied to clipboard
fix(deps): update dependency minimist to v1.2.6 [security]
This PR contains the following updates:
Package | Change | Age | Adoption | Passing | Confidence |
---|---|---|---|---|---|
minimist | 1.2.0 -> 1.2.6 |
GitHub Vulnerability Alerts
CVE-2020-7598
Affected versions of minimist
are vulnerable to prototype pollution. Arguments are not properly sanitized, allowing an attacker to modify the prototype of Object
, causing the addition or modification of an existing property that will exist on all objects.
Parsing the argument --__proto__.y=Polluted
adds a y
property with value Polluted
to all objects. The argument --__proto__=Polluted
raises and uncaught error and crashes the application.
This is exploitable if attackers have control over the arguments being passed to minimist
.
Recommendation
Upgrade to versions 0.2.1, 1.2.3 or later.
CVE-2021-44906
Minimist prior to 1.2.6 and 0.2.4 is vulnerable to Prototype Pollution via file index.js
, function setKey()
(lines 69-95).
Release Notes
minimistjs/minimist (minimist)
v1.2.6
Commits
- test from prototype pollution PR
bc8ecee
- isConstructorOrProto adapted from PR
c2b9819
- security notice for additional prototype pollution issue
ef88b93
v1.2.5
v1.2.4
Commits
v1.2.3
Commits
- more failing proto pollution tests
13c01a5
- even more aggressive checks for protocol pollution
38a4d1c
v1.2.2
Commits
- failing test for protocol pollution
0efed03
- cleanup
67d3722
- console.dir -> console.log
47acf72
- don't assign onto proto
63e7ed0
v1.2.1
Merged
- move the
opts['--']
example back where it belongs#63
Commits
Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
- [ ] If you want to rebase/retry this PR, check this box
This PR was generated by Mend Renovate. View the repository job log.