Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Dependency vulnerability with CVSS 7.5 with braces v3.0.2 #1331

Closed
xLexip opened this issue Jun 27, 2024 · 2 comments
Closed

Dependency vulnerability with CVSS 7.5 with braces v3.0.2 #1331

xLexip opened this issue Jun 27, 2024 · 2 comments

Comments

@xLexip
Copy link

xLexip commented Jun 27, 2024

The latest version of this project uses braces v3.0.2 which is vulnerable to CVE-2024-4068. Severity 7.5 (high).
The issue was fixed with braces#40 in a patch release (v3.0.3).

Please consider updating braces from v3.0.2 to v3.0.3 as chokidar forwards this vulnerability to other projects like @wdio/cli.

@xLexip xLexip changed the title Dependency vulnerability with CVSS 7.5 (high) with braces v3.0.2 Dependency vulnerability with CVSS 7.5 (high) with braces v3.0.2 (CVE-2024-4068) Jun 27, 2024
@paulmillr
Copy link
Owner

learn how version ranges work

@paulmillr paulmillr closed this as not planned Won't fix, can't repro, duplicate, stale Jun 27, 2024
@xLexip xLexip changed the title Dependency vulnerability with CVSS 7.5 (high) with braces v3.0.2 (CVE-2024-4068) Dependency vulnerability with CVSS 7.5 with braces v3.0.2 Jun 27, 2024
@xLexip
Copy link
Author

xLexip commented Jun 27, 2024

My bad. 🤡 I trusted npm ls too much.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants