cloudsploit icon indicating copy to clipboard operation
cloudsploit copied to clipboard

Bump node-forge 0.9.1 to 0.10.0, fix high severity vulnerability

Open ne0z opened this issue 3 years ago • 1 comments

The package node-forge before 0.10.0 is vulnerable to Prototype Pollution with high severity. To fix this vulnerability we need to upgrade node-forge to 0.10.0.

Reference: https://www.npmjs.com/advisories/1561

ne0z avatar Apr 13 '21 19:04 ne0z

CLA assistant check
Thank you for your submission! We really appreciate it. Like many open source projects, we ask that you sign our Contributor License Agreement before we can accept your contribution.
You have signed the CLA already but the status is still pending? Let us recheck it.

CLAassistant avatar Apr 13 '21 19:04 CLAassistant