Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Found Vulnerability ' Improper Input Validation ' and ' Prototype Pollution ' on Synk.io #125

Open
kanxoramesh opened this issue Oct 27, 2021 · 3 comments

Comments

@kanxoramesh
Copy link

kanxoramesh commented Oct 27, 2021

BUG

Synk.io is reporting Vulnerability for this library, One of the dependence library saml@1.0.0 uses xmldom which has Vulnerability.
and also Arbitrary Code Injection from package ejs@3.1.6

Solution: update dependence library saml@1.0.0 to 1.0.1 which is using the latest version of xmldom@0.7.4 and also update ejs@2.5.5 to ejs@3.1.6

@kanxoramesh kanxoramesh changed the title Found Vulnerability ' Improper Input Validation ' and ' Prototype Pollution ' Found Vulnerability ' Improper Input Validation ' and ' Prototype Pollution ' on Sunk.io Oct 28, 2021
@kanxoramesh kanxoramesh changed the title Found Vulnerability ' Improper Input Validation ' and ' Prototype Pollution ' on Sunk.io Found Vulnerability ' Improper Input Validation ' and ' Prototype Pollution ' on Synk.io Oct 28, 2021
@RopoMen
Copy link

RopoMen commented Apr 28, 2022

Github Advisory: GHSA-phwq-j96m-2c2q

@aaronsegstro
Copy link

SAML Was updated but there's still critical vulnerabilities in ejs@2.5.5 that would be corrected by updating to ejs@3.1.8

@decko
Copy link

decko commented Jul 21, 2022

Hi @aaronsegstro. I just submitted a PR bumping ejs to 3.1.8 here #130.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants