Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bug(security): auditjs reports vulnerability in dependency - flat@5.0.2 #570

Closed
1 task done
JostHren opened this issue May 31, 2022 · 6 comments
Closed
1 task done

Comments

@JostHren
Copy link

JostHren commented May 31, 2022

Is there an existing issue for this?

  • I have searched the existing issues

Which Transloco package(s) are the source of the bug?

Transloco

Is this a regression?

No

Current behavior

Auditjs reports vulnerability in dependency - flat@5.0.2.

Expected behavior

No vulnerability reported.

Please provide a link to a minimal reproduction of the bug

https://ossindex.sonatype.org/vulnerability/sonatype-2020-0889?component-type=npm&component-name=flat&utm_source=auditjs&utm_medium=integration&utm_content=4.0.37

Transloco Config

No response

Please provide the environment you discovered this bug in

Transloco: 
Angular: 
Node: 
Package Manager: 
OS:

Browser

No response

Additional context

AuditJS message:

[115/281] - pkg:npm/flat@5.0.2 - 1 vulnerability found!
  Vulnerability Title:  [sonatype-2020-0889] CWE-471: Modification of Assumed-Immutable Data (MAID)
  ID:  sonatype-2020-0889
  Description:  flat - Prototype Pollution
  
  The software does not properly protect an assumed-immutable element from being modified by an attacker.
  CVSS Score:  7.5
  CVSS Vector:  CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
  Reference:  https://ossindex.sonatype.org/vulnerability/sonatype-2020-0889?component-type=npm&component-name=flat&utm_source=auditjs&utm_medium=integration&utm_content=4.0.37

I would like to make a pull request for this bug

No

@shaharkazaz
Copy link
Collaborator

@JostHren Transloco is using the latest flat version. If they make a fix, I'll update the package as well.
You are welcome to open an issue at the flat repo

@enrique-lozano
Copy link

Hi! Seems to be a new version available (v6.0) https://github.com/hughsk/flat/tags

@shaharkazaz
Copy link
Collaborator

@enrique-lozano It's only the tag in the repository, not the actual release. in NPM the latest version is still 5.0.2

@SamuelKnoch
Copy link

Version 6 with ECMAScript module now released on NPM

@shaharkazaz
Copy link
Collaborator

@SamuelKnoch Yes I'm tracked the issue as well 🙂 I'll release a version today

@SamuelKnoch
Copy link

@shaharkazaz thank you very much

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants