Skip to content

Conversation

@bytestream
Copy link
Collaborator

Description

CVE-2020-7598
moderate severity
Vulnerable versions: < 0.2.1
Patched version: 0.2.1

minimist before 1.2.2 could be tricked into adding or modifying properties of Object.prototype using a "constructor" or "proto" payload.

@bytestream bytestream added the dependencies Pull requests that update a dependency file label Jun 22, 2020
@bytestream bytestream merged commit f9b2113 into proengsoft:master Jun 22, 2020
@bytestream bytestream added the javascript Pull requests that update Javascript code label Jun 23, 2020
@bytestream bytestream deleted the minimist branch June 23, 2020 11:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update Javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant