-
Notifications
You must be signed in to change notification settings - Fork 768
Closed
Labels
duplicateThis issue or pull request already existsThis issue or pull request already exists
Description
Recently log4j a java logging library has been reported as zero day vulnerability security threat. Can 'log4js' a node logging framework be a security threat too. ?? If yes , My node application is using 'karma' as a devdependency and 'log4js' is a nested dependency inside karma. Can this pose any security threat to my application. If yes how can I mitigate this ??? I am using karma to run test cases locally.
xinthose
Metadata
Metadata
Assignees
Labels
duplicateThis issue or pull request already existsThis issue or pull request already exists