Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

CVE-2022-46175 - High #252

Open
ldco2016 opened this issue Jan 4, 2024 · 1 comment
Open

CVE-2022-46175 - High #252

ldco2016 opened this issue Jan 4, 2024 · 1 comment

Comments

@ldco2016
Copy link

ldco2016 commented Jan 4, 2024

Guys, we are using a dependency called svg-inline-loader which is using loader-utils@.4.2 which seems to be using json5@1.0.2 and since svg-inline-loader version we are using is the latest one, we would need for loader-utils to be on a version that is using a json5 version where the CVE has been patched or perhaps a version not needing that dependency at all.

Could you please advise as we need to resolve these vulnerabilities as soon as possible.

@alexander-akait
Copy link
Member

loader-utils is deprecated and should not used in loader anymore, also loader-utils@0.4.2 is outdated and this CVE was fixed in the last version, so please ask developer(s) of svg-inline-loader update deps

# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants