-
Notifications
You must be signed in to change notification settings - Fork 1
Open
Description
Find more live information in Aikido here: https://app.aikido.dev/queue?sidebarIssue=16045354&groupId=37390&sidebarIssueTask=1268629&sidebarTab=tasks
Scope
This task includes issues in the following code repository:
- ts-defold.github.io: yarn.lock
TLDR
Prototype pollution vulnerability in function parseQuery in parseQuery.js in webpack loader-utils via the name variable in parseQuery.js. This affects all versions prior to 1.4.1 and 2.0.3.
How to fix
We recommend updating from 2.0.0 to 2.0.3.