Skip to content

bump loader-utils@^2.0.4 #2015

New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

Open
wants to merge 2 commits into
base: main
Choose a base branch
from
Open

bump loader-utils@^2.0.4 #2015

wants to merge 2 commits into from

Conversation

kjakub
Copy link

@kjakub kjakub commented Nov 17, 2022

high │ loader-utils is vulnerable to Regular Expression Denial of │
│ │ Service (ReDoS) via url variable │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Package │ loader-utils │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Patched in │ >=2.0.4 │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Dependency of │ vue-loader │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Path │ vue-loader > loader-utils │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ More info │ https://www.npmjs.com/advisories/1084992

@kjakub
Copy link
Author

kjakub commented Nov 25, 2022

@sodatea

# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants