-
Notifications
You must be signed in to change notification settings - Fork 256
Open
Description
Hello, I got the github issue report that node-forge in adbkit needs to version up due to follow.
CVE-2020-7720
Vulnerable versions: < 0.10.0
Patched version: 0.10.0
The package node-forge before 0.10.0 is vulnerable to Prototype Pollution via the util.setPath function. Note: Version 0.10.0 is a breaking change removing the vulnerable functions.
Please update the node-forge version 0.10.0 or later.
ftassy
Metadata
Metadata
Assignees
Labels
No labels