You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Short story: requirejs@2.3.6 is the latest version from Aug 27, 2018. Not possible to do a quick fix by using an override in the ' package.json' until that project updates or something higher in the chain drops it. Example:
"overrides": {
"module-lookup-amd": {
"requirejs": "some later version here"
}
},
requirejs/r.js#1015
Medium severity
requirejs Prototype Pollution
VULNERABILITY
CWE-1321OPEN THIS LINK IN A NEW TAB
CVSS 6.5OPEN THIS LINK IN A NEW TAB MEDIUM
SNYK-JS-REQUIREJS-5416713OPEN THIS LINK IN A NEW TAB
SCORE
432
Introduced through
madge@7.0.0
Exploit maturity
PROOF OF CONCEPT
Show less detail
Detailed paths
Introduced through: cshs@0.1.0 › madge@7.0.0 › dependency-tree@10.0.9 › filing-cabinet@4.2.0 › module-lookup-amd@8.0.5 › requirejs@2.3.6
Fix: No remediation path available.
The text was updated successfully, but these errors were encountered: