-
Notifications
You must be signed in to change notification settings - Fork 165
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Vulnerability in depencies (xmldom) #234
Comments
is this issue exploitable in Clever/saml2 |
It seems so: https://mattermost.com/blog/securing-xml-implementations-across-the-web/ |
As per xmldom/xmldom#271 (and in order to stay safe from a vulnerability in 0.6.0), the recommended now would be to update to |
Should be resolved once this is merged. #245 There is a xmldom 0.8.0 release. Might be wirth using the latest version now. |
Don't know if it has been already posted elsewhere, but you can fix the vulnerability issue by overriding the used xmldom:
At the moment, it seems to work fine with this override in my case. |
Addressed in #261. |
Could you please update to version 0.5.0 or later as per https://www.npmjs.com/advisories/1650
Thank you!
The text was updated successfully, but these errors were encountered: