Skip to content

High sev vulnerability caused by outdated express version #34

@imanjra

Description

@imanjra

Outdated version (4.14.0) of express contains dependencies with high severity vulnerabilities:

✗ High severity vulnerability found in qs
  Description: Prototype Override Protection Bypass
  From: json-proxy@0.9.3 > express@4.14.1 > qs@6.2.0

✗ High severity vulnerability found in fresh
  Description: Regular Expression Denial of Service (ReDoS)
  From: json-proxy@0.9.3 > express@4.14.1 > fresh@0.3.0
  From: json-proxy@0.9.3 > express@4.14.1 > send@0.14.2 > fresh@0.3.0
  From: json-proxy@0.9.3 > express@4.14.1 > serve-static@1.11.2 > send@0.14.2 > fresh@0.3.0

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions