You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
xml2js 0.5.0 has been released, and the upstream issue has been closed as fixed, so a bump is probably all that is needed.
Kurt-von-Laven
changed the title
Sever Dependency On xml2js to Prevent Prototype Pollution
Bump Dependency On xml2js to Prevent Prototype Pollution
Apr 10, 2023
Package Version: 2.6.4
Describe the bug
xml2js <= 0.4.23
contains a recently disclosed high severity security vulnerability. No patched version is available, and xml2js has not seen a release since 2019. The issue in xml2js is Leonidas-from-XIV/node-xml2js#663.To Reproduce
Steps to reproduce the behavior:
yarn npm audit --all --recursive
, or the equivalent command in your chosen package manager.Expected behavior
No security vulnerabilities are detected.
Additional context
I suspect other
@azure
packages also depend on xml2js.The text was updated successfully, but these errors were encountered: