timeoff-management-application icon indicating copy to clipboard operation
timeoff-management-application copied to clipboard

Found 15 vulnerabilities (3 low, 1 moderate, 11 high)

Open miriamlarsson opened this issue 5 years ago • 1 comments

I wanted to run a self hosted version of this app and found 15 security issues when I installed it. They would all require major version updates, is this something that's being looked into?

miriamlarsson avatar Feb 06 '20 09:02 miriamlarsson

Well... The main one is Sequelize.

However the venerability in the feature the application does not rely on.

So it is kind of Ok to tolerate it.

To update the Sequelize is not easy as the app relies on the interfaces the library abandoned in newer versions.

vpp avatar Feb 06 '20 15:02 vpp