Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Latest release uses vulnerable axios version (CVE-2024-39338) #242

Closed
milenkotomic opened this issue Aug 12, 2024 · 3 comments · Fixed by #243
Closed

Latest release uses vulnerable axios version (CVE-2024-39338) #242

milenkotomic opened this issue Aug 12, 2024 · 3 comments · Fixed by #243
Assignees
Labels
bug Something isn't working

Comments

@milenkotomic
Copy link

Description

Latest @newrelic/security-agent version uses vulnerable axios package version 1.6.8 CVE-2024-39338

Expected Behavior

Please upgrade @newrelic/security-agent to use axios >= 1.7.3

@milenkotomic milenkotomic added the bug Something isn't working label Aug 12, 2024
@sumitsuthar
Copy link
Contributor

sumitsuthar commented Aug 13, 2024

Axios has not released a fix for this yet

@sumitsuthar sumitsuthar self-assigned this Aug 13, 2024
@Irene350
Copy link

Any news on this one?

@sumitsuthar
Copy link
Contributor

@Irene350 Axios has still not fixed the issue. PR is still open.
axios/axios#6539.
once axios publish a new version we will release ASAP

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working
Projects
None yet
Development

Successfully merging a pull request may close this issue.

3 participants