Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

High level security vulnerabilities in version 19.14.16 of HOF relating to underscore library #349

Open
johndallen opened this issue Sep 8, 2022 · 0 comments

Comments

@johndallen
Copy link
Contributor

On latest build using Node v14.18.1 the follwing 5 security vulnerabilities are reported:

underscore 1.3.2 - 1.12.0
Severity: high
Arbitrary Code Execution in underscore - GHSA-cf4h-3jhx-xvhq
fix available via npm audit fix --force
Will install hof@18.3.0, which is a breaking change
node_modules/httpntlm/node_modules/underscore
httpntlm 1.5.0 - 1.7.6
Depends on vulnerable versions of underscore
node_modules/httpntlm
smtp-connection 2.4.0-beta.0 - 3.2.0
Depends on vulnerable versions of httpntlm
node_modules/smtp-connection
nodemailer-smtp-transport 2.0.0-beta.0 - 2.0.0-beta.1 || >=2.5.0
Depends on vulnerable versions of smtp-connection
node_modules/nodemailer-smtp-transport
hof >=19.0.0-beta-v1
Depends on vulnerable versions of nodemailer-smtp-transport
node_modules/hof

5 high severity vulnerabilities

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant