Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security: Update underscore.js #148

Closed
hedsnz opened this issue Sep 9, 2022 · 1 comment
Closed

Security: Update underscore.js #148

hedsnz opened this issue Sep 9, 2022 · 1 comment

Comments

@hedsnz
Copy link

hedsnz commented Sep 9, 2022

The included version of underscore.js, 1.7.0, is vulnerable to an arbitrary code injection attack CVE-2021-23358.

This is fixed is underscore.js 1.12.1.

I suggest we update to the latest underscore release, 1.13.4. Would you accept a PR for this?

@hedsnz
Copy link
Author

hedsnz commented May 4, 2023

@jeroen looks like you've added underscore.js back in, but updated it to 1.13.6: dff09bc. I think the way it's included in the linked PR would make it easier to update in the future, but in any case I'll close this as completed now.

@hedsnz hedsnz closed this as completed May 4, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant