Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore(deps): bump sanitize-html, fixing CVE-2024-21501 #7662

Merged
merged 2 commits into from
Mar 5, 2024

Conversation

etnoy
Copy link
Contributor

@etnoy etnoy commented Mar 5, 2024

Versions of the package sanitize-html before 2.12.1 are vulnerable to Information Exposure when used on the backend and with the style attribute allowed, allowing enumeration of files in the system (including project dependencies). An attacker could exploit this vulnerability to gather details about the file system structure and dependencies of the targeted server.

Bumps sanitize-html to 2.12.1

@etnoy etnoy added the dependencies Pull requests that update a dependency file label Mar 5, 2024
Copy link

cloudflare-pages bot commented Mar 5, 2024

Deploying with  Cloudflare Pages  Cloudflare Pages

Latest commit: d29c85f
Status: ✅  Deploy successful!
Preview URL: https://9dbd9f64.immich.pages.dev
Branch Preview URL: https://chore-cve-2024-21501.immich.pages.dev

View logs

@jrasm91 jrasm91 merged commit ae46188 into main Mar 5, 2024
25 checks passed
@jrasm91 jrasm91 deleted the chore/CVE-2024-21501 branch March 5, 2024 22:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants