-
Notifications
You must be signed in to change notification settings - Fork 30
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[BUG] CVE-2021-27290 due to using old version of ssri
#47
Comments
Since |
this module has been updated and the next cli release will include this change |
@wraithgar Thanks a ton for this fix. Is it possible to also update the |
@wraithgar Strapi also depends on |
+1 for adding this patch into v12 |
I attempted to backport the bump to v12 and opened a PR, but all the tests that passed for me locally failed in CI. I'm not intimately familiar with node development, so maybe someone more knowledgeable would be able to help me get that in a passing state. |
@Zajn Thanks for opening that PR. I spun it up locally but am also getting failing tests. In the Something else I'm wondering about: According to the vulnerability report, "this issue only affects consumers using the strict option." Does Finally, I started an issue in the |
@AndrewGibson27 Both good points. I don't know enough about the project to definitively say yes or no to the usage of I've never done any Node development, so I may have run the tests improperly which gave me a passing result. Locally, I just installed dependencies via
Thanks for doing that! |
FYI ssri v6.0.2 released. |
Can you please make new releases when this issue is fixed?
Versions
15.0.6
and12.0.5
(a12.x
release would be nice because many projects depend oncache
12.x
).What / Why
CVE-2021-27290
The fix is to bump
ssri
to8.0.1
.When
Where
How
Current Behavior
Steps to Reproduce
Expected Behavior
Who
References
The text was updated successfully, but these errors were encountered: