Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Please upgrade this vulnerable package #694

Closed
PabloJomer opened this issue Jul 6, 2021 · 2 comments
Closed

Please upgrade this vulnerable package #694

PabloJomer opened this issue Jul 6, 2021 · 2 comments

Comments

@PabloJomer
Copy link

"ecstatic": "^3.3.2",

Dependabot marks this as an issue:

Remediation
Upgrade ecstatic to version 4.1.3 or later. For example:

ecstatic@^4.1.3:
version "4.1.3"
Always verify the validity and compatibility of suggestions with your codebase.

Details
CVE-2019-10775
moderate severity
Vulnerable versions: < 4.1.3
Patched version: 4.1.3
ecstatic have a denial of service vulnerability. Successful exploitation could lead to crash of an application.

For more details see:

GHSA-jc84-3g44-wf2q

@zbynek
Copy link
Contributor

zbynek commented Jul 6, 2021

There were multiple attempts to do that, the latest one #693 may finally work.

@thornjad thornjad mentioned this issue Jul 6, 2021
2 tasks
@thornjad
Copy link
Member

thornjad commented Jul 6, 2021

Duplicate of #568

@thornjad thornjad marked this as a duplicate of #568 Jul 6, 2021
@thornjad thornjad closed this as completed Jul 6, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants