Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

Urgent matter #1

Closed
Cyber-Dude1 opened this issue Apr 22, 2021 · 8 comments
Closed

Urgent matter #1

Cyber-Dude1 opened this issue Apr 22, 2021 · 8 comments

Comments

@Cyber-Dude1
Copy link

Cyber-Dude1 commented Apr 22, 2021

Hi there,
Can you please contact me by mail?

Thanks.

@Cyber-Dude1 Cyber-Dude1 changed the title Prototype Pollution in Mixme Urgent matter Apr 22, 2021
@Cyber-Dude1 Cyber-Dude1 reopened this Apr 22, 2021
wdavidw added a commit that referenced this issue Apr 25, 2021
@wdavidw
Copy link
Member

wdavidw commented Apr 25, 2021

Thank you @Cyber-Dude1 for reporting this vulnerability. Version 0.5.1 fixes this issue.

@wdavidw wdavidw closed this as completed Apr 25, 2021
@Cyber-Dude1
Copy link
Author

Cyber-Dude1 commented Apr 26, 2021 via email

@wdavidw
Copy link
Member

wdavidw commented Apr 26, 2021 via email

@Cyber-Dude1
Copy link
Author

Cyber-Dude1 commented Apr 26, 2021 via email

@wdavidw
Copy link
Member

wdavidw commented Apr 26, 2021 via email

@Cyber-Dude1
Copy link
Author

Cyber-Dude1 commented May 5, 2021

Hi David,
Sorry for the late reply..
So, the best way of doing so is to create a security advisory for this repo (in GitHub). Once it will be submitted, NPM team will review.
You can follow the steps described here.

Thanks :)

@Cyber-Dude1
Copy link
Author

Hi David,
Please notice that CVE-2021-28860 got assigned for this vulnerability.

@wdavidw
Copy link
Member

wdavidw commented May 5, 2021

Yes, I got the notification. My understanding is that the NPM team will get notified and take further actions without the need to contact them.

# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants