Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[BUG] fast-xml-parser has a vulnerability #573

Closed
1 task done
Tracked by #581
jdforsythe opened this issue Jun 23, 2023 · 1 comment
Closed
1 task done
Tracked by #581

[BUG] fast-xml-parser has a vulnerability #573

jdforsythe opened this issue Jun 23, 2023 · 1 comment
Labels
Bug thing that needs fixing Needs Triage needs an initial review

Comments

@jdforsythe
Copy link

Is there an existing issue for this?

  • I have searched the existing issues

Current Behavior

┌───────────────┬──────────────────────────────────────────────────────────────┐
│ low           │ fast-xml-parser regex vulnerability patch could be improved  │
│               │ from a safety perspective                                    │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Package       │ fast-xml-parser                                              │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Patched in    │ >=4.2.5                                                      │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Dependency of │ @sensource/parse-xovis-status                                │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Path          │ @sensource/parse-xovis-status > fast-xml-parser              │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ More info     │ https://www.npmjs.com/advisories/1092317                     │
└───────────────┴──────────────────────────────────────────────────────────────┘

Expected Behavior

Bump the dependency to >= 4.2.5

Steps To Reproduce

  1. In this environment...
  2. With this config...
  3. Run '...'
  4. See error...

Environment

  • npm:
  • Node:
  • OS:
  • platform:
@jdforsythe jdforsythe added Bug thing that needs fixing Needs Triage needs an initial review labels Jun 23, 2023
@jdforsythe
Copy link
Author

nevermind... haha

@Gornator Gornator mentioned this issue Jul 2, 2023
1 task
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Bug thing that needs fixing Needs Triage needs an initial review
Projects
None yet
Development

No branches or pull requests

1 participant