Skip to content

Security vulnerability of medium severity in react script module for inflight transitive dependency  #13336

@wesco-vishalprasad

Description

@wesco-vishalprasad

When i create a create react app i found a medium security vulnerability in inflight library https://www.npmjs.com/package/inflight?activeTab=versions, the details are below
Veracode Software Composition Analysis(SCA) scan screenshot
Screenshot 2023-08-22 at 5 01 00 PM
SRCCLR-SID-41137
Memory Leak: inflight is vulnerable to a Memory Leak. The vulnerability is due to lack of restriction
s on how many callbacks the library can concurrently support, which can result in a NodeJS out of heap memory crash.
We scanned using a licensed version of veracode tool
Inflight is no more maintained and react-script latest version 5.0.1 has this vulnerability
Please let us know if this can be fixed or any work around

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions