Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

tmpl vulnerability in package-lock.json #371

Closed
palisadoes opened this issue Nov 23, 2021 · 0 comments · Fixed by #397
Closed

tmpl vulnerability in package-lock.json #371

palisadoes opened this issue Nov 23, 2021 · 0 comments · Fixed by #397
Labels
bug Something isn't working good first issue Good for newcomers security Security fix wip Work in Progress

Comments

@palisadoes
Copy link
Contributor

Describe the bug

nodejs-tmpl is vulnerable to Inefficient Regular Expression Complexity which may lead to resource exhaustion.

Parent issue

Remediation
The earliest fixed version is 1.0.5.

Screenshots
image

References
GHSA-jgrx-mgxx-jf9v

@github-actions github-actions bot added bug Something isn't working parent Parent issue unapproved Unapproved for Pull Request labels Nov 23, 2021
@palisadoes palisadoes added security Security fix good first issue Good for newcomers and removed parent Parent issue labels Nov 23, 2021
@sumitra19jha sumitra19jha removed the unapproved Unapproved for Pull Request label Nov 23, 2021
@palisadoes palisadoes added the wip Work in Progress label Dec 28, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working good first issue Good for newcomers security Security fix wip Work in Progress
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants