You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The text was updated successfully, but these errors were encountered:
janzelc-trifecta
changed the title
Security - dependency "underscore" prior to version 1.12.1 allow arbitrary code execution
Security - dependency "underscore" prior to version 1.12.1 allows arbitrary code execution
Jun 2, 2023
Looks like the function in question (template, from jashkenas/underscore#2915) must be specifically called.
Additionally, package.json refers to underscore via ^1.8.0. Semantic versioning will pull in the latest version underneath that major version, which is currently 1.13.6.
This issue does not seem to be valid for this package. Please comment if that is not the case.
https://nvd.nist.gov/vuln/detail/CVE-2021-23358
The text was updated successfully, but these errors were encountered: