Skip to content

Dependency Underscore -1.9.1 has CRITICAL Vulnerability - Arbitrary Code Execution in underscore which has patched in >=1.12.1 versions of underscore #1817

New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

Open
Shobha-Potti opened this issue Apr 22, 2024 · 0 comments
Assignees

Comments

@Shobha-Potti
Copy link

Shobha-Potti commented Apr 22, 2024

when I use this package react-bootstrap-table-next in create-react-app project.

when checking for vulnerabilities in the terminal

npm audit

I am encountering this error

┌───────────────┬──────────────────────────────────────────────────────────────┐
│ Critical │ Arbitrary Code Execution in underscore │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Package │ underscore │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Patched in │ >=1.12.1 │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Dependency of │ react-bootstrap-table-next │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Path │ react-bootstrap-table-next > underscore │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ More info │ GHSA-cf4h-3jhx-xvhq
├───────────────┼───────────────────────────────────────

# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants