Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Critical Vulnerability in getobject (direct dependency) #31

Closed
jmac105 opened this issue Jan 22, 2021 · 10 comments
Closed

Critical Vulnerability in getobject (direct dependency) #31

jmac105 opened this issue Jan 22, 2021 · 10 comments

Comments

@jmac105
Copy link

jmac105 commented Jan 22, 2021

There is a critical (CVSS 9.8) vulnerability in getobject version 0.1.0, with no patched version available. See https://nvd.nist.gov/vuln/detail/CVE-2020-28282

@ghost
Copy link

ghost commented Mar 3, 2021

Any plans on addressing this?

@vladikoff
Copy link
Member

fixed in 59a9539

@yanivNaor92
Copy link

@vladikoff, thanks for the fix.
Is there a planned release to npmjs.com for this fix?

@vladikoff
Copy link
Member

@yanivNaor92 yeap it's in the works

@rlindner81
Copy link

@vladikoff also waiting on this... no rush ;)

@mileacolaco
Copy link

@vladikoff We are currently facing vulnerability issues due to this dependency and would like to know what is the planned date for releasing the upgraded grunt-legacy-util to the npm registry. It would be of great help if this can be intimated.

@kuba-kubula
Copy link

@vladikoff even though the fix was merged, the package was not released since with the fixed dependencies. Please, release it.

@vladikoff
Copy link
Member

vladikoff commented Apr 22, 2021 via email

@mileacolaco
Copy link

@vladikoff thank you for making the release available. Appreciate the quick response.

@kuba-kubula
Copy link

@vladikoff Big thanks. One less CVE in the sky

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

6 participants