You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
There is a CVE for xmlhttprequest and xmlhttprequest-ssl that is used in ember-fedora-adapter and ember. This is categorized as a critical arbitrary code injection vulnerability.
All versions of xmlhttprequest-ssl are vulnerable. There is an issue created here 12 days ago but no response from the dev. Project looks abandoned as nothing has been pushed/merged for +3 years.
There is a CVE for xmlhttprequest and xmlhttprequest-ssl that is used in ember-fedora-adapter and ember. This is categorized as a critical arbitrary code injection vulnerability.
GitHub advisory: GHSA-h4j5-c7cj-74xg
Snyk: https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1082937
Snyk (ssl): https://snyk.io/vuln/SNYK-JS-XMLHTTPREQUESTSSL-1082936
NVD: https://nvd.nist.gov/vuln/detail/CVE-2020-28502
Recommendation is that we upgrade post 1.7.0 of xmlhttprequest and the latest xmlhttprequest-ssl
The text was updated successfully, but these errors were encountered: