-
-
Notifications
You must be signed in to change notification settings - Fork 33
Closed
Labels
Resolution: FixedThe issue has been fixed.The issue has been fixed.Status: ReleasedIt's now live.It's now live.Status: TriageThis issue needs to be triaged.This issue needs to be triaged.Type: BugInconsistencies or issues which will cause a problem for users or implementors.Inconsistencies or issues which will cause a problem for users or implementors.
Description
Bug Report
deepmerge-js < 4.0.2 apparently contains a Prototype Pollution security vulnerability as reported in
https://security.snyk.io/vuln/SNYK-JS-DEEPMERGETS-2438399
https://nvd.nist.gov/vuln/detail/CVE-2022-24802
Proposed changes
Update the deepmerge-js to version >= 4.0.2 in package.json
Thank you!
Metadata
Metadata
Assignees
Labels
Resolution: FixedThe issue has been fixed.The issue has been fixed.Status: ReleasedIt's now live.It's now live.Status: TriageThis issue needs to be triaged.This issue needs to be triaged.Type: BugInconsistencies or issues which will cause a problem for users or implementors.Inconsistencies or issues which will cause a problem for users or implementors.