Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE on Dependencies ip, fast-xml-parser #3

Open
martindale opened this issue Feb 20, 2024 · 0 comments
Open

CVE on Dependencies ip, fast-xml-parser #3

martindale opened this issue Feb 20, 2024 · 0 comments

Comments

@martindale
Copy link

npm audit report

fast-xml-parser <4.1.2
Severity: moderate
fast-xml-parser vulnerable to Prototype Pollution through tag or attribute name - GHSA-x3cc-x39p-42qx
No fix available
node_modules/fast-xml-parser
nat-upnp-2 *
Depends on vulnerable versions of fast-xml-parser
Depends on vulnerable versions of ip
node_modules/nat-upnp-2

ip <=2.0.0
Severity: high
NPM IP package vulnerable to Server-Side Request Forgery (SSRF) attacks - GHSA-78xj-cgh5-2h22
fix available via npm audit fix
node_modules/ip

3 vulnerabilities (1 moderate, 2 high)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant