Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

rfc6902 prototype pollution #84

Closed
sruthy-s-rft opened this issue Aug 6, 2021 · 2 comments
Closed

rfc6902 prototype pollution #84

sruthy-s-rft opened this issue Aug 6, 2021 · 2 comments

Comments

@sruthy-s-rft
Copy link

As per veracode scans, this library is subject to prototype pollution.
https://sca.analysiscenter.veracode.com/vulnerability-database/security/sca/vulnerability/sid-28898/summary

Is there a plan to fix this in the upcoming release.

@aleung
Copy link

aleung commented Oct 25, 2021

There is PR #76 but not being merged after months.

@chbrown
Copy link
Owner

chbrown commented Dec 16, 2021

Uggh okay fine, fixed in v5.0.0 just now.

@chbrown chbrown closed this as completed Dec 16, 2021
# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants