Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

node package for snowboy contains a vulnerability #477

Open
chemdrew opened this issue Jul 18, 2018 · 0 comments
Open

node package for snowboy contains a vulnerability #477

chemdrew opened this issue Jul 18, 2018 · 0 comments

Comments

@chemdrew
Copy link

default installation dependency tree in error

snowboy@1.3.1
└─┬ node-pre-gyp@0.6.39
  └─┬ hawk@3.1.3
    └── hoek@2.16.3

Where hoek <5.0.3 || <4.2.1 suffer from a Modification of Assumed-Immutable Data (MAID) vulnerability. More info can be found here https://nvd.nist.gov/vuln/detail/CVE-2018-3728

Hopefully the newer versions of node-pre-gyp are compatible and that can just be updated.

# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant