lite-server icon indicating copy to clipboard operation
lite-server copied to clipboard

The package needs to update axios to solve high severity vulnerability

Open aliataf opened this issue 4 years ago • 1 comments

A Server-Side Request Forgery (SSRF) vulnerability was found in axios which is a dependency of lite-server. It is patched in version >=0.21.1 so lite-server should update axios.

aliataf avatar Jan 08 '21 22:01 aliataf

The fix here is to upgrade browser-sync to current (3.0.2 as of this comment) as it drops dependency for localtunnel which is dependant on the vulnerable version of axios

PseudoNinja avatar Apr 25 '24 22:04 PseudoNinja