2.4.1
What's Changed
- CVE-2024-38999 requirejs v2.3.6 was discovered to contain a prototype pollution via the function s.contexts._.configure. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties by @maximthomas in #153
- move javax.version to servlet-api.version property in maven by @maximthomas in #152
Full Changelog: 2.4.0...2.4.1