Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

normalize-url - Denial of Service high vulnerability #9419

Closed
kbagnall opened this issue Jun 9, 2021 · 1 comment
Closed

normalize-url - Denial of Service high vulnerability #9419

kbagnall opened this issue Jun 9, 2021 · 1 comment

Comments

@kbagnall
Copy link

kbagnall commented Jun 9, 2021

Versions

  • nuxt: 2.15.6
  • node: 14.17

Reproduction

npm install we're prompted with High vulnerability of normalize-url Nuxt dependency.
npm list | grap shows us that Nuxt 2.15.6 - @nuxt/webpack@2.15.6 is dependent on normalize-url@3.0.0 and needs to be upgraded to 6.0.1

Steps to reproduce

npm install

image

https://snyk.io/vuln/SNYK-JS-NORMALIZEURL-1296539

What is Expected?

no high vulnerabilities

What is actually happening?

high vulnerabilities for normalise-url

Copy link
Member

@kbagnall I've updated #9284 - hope this helps 🙃

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants