Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Vulnerability issue in used "node-fetch" version 2.6.1 #1624

Closed
devashish-s opened this issue Jul 5, 2024 · 1 comment
Closed

Vulnerability issue in used "node-fetch" version 2.6.1 #1624

devashish-s opened this issue Jul 5, 2024 · 1 comment
Assignees
Labels
priority: p2 Moderately-important priority. Fix may not be included in next release. type: bug Error or flaw in code with unintended results or allowing sub-optimal usage patterns.

Comments

@devashish-s
Copy link

Hi there,

We are using google-gax in our project deployed on GCP account. in our yearly report we are getting issue with npm package node-fetch (^2.6.1) that should be update version 2.6.7 or higher.

Environment details

"The library node-fetch version 2.6.1 was detected in NPM library manager located at package-lock.json and is vulnerable to CVE-2022-0235, which exists in versions < 2.6.7.

The vulnerability was found in the Github Security Advisory with vendor severity: High (NVD severity: Medium).

The vulnerability can be remediated by updating the library to version 2.6.7 or higher."

Thanks!

@devashish-s devashish-s added priority: p2 Moderately-important priority. Fix may not be included in next release. type: bug Error or flaw in code with unintended results or allowing sub-optimal usage patterns. labels Jul 5, 2024
@devashish-s devashish-s changed the title Issue in used "node-fetch" version 2.6.1 Vulnerability issue in used "node-fetch" version 2.6.1 Jul 10, 2024
@danielbankhead
Copy link
Contributor

Fixed via #1638

@danielbankhead danielbankhead self-assigned this Aug 7, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
priority: p2 Moderately-important priority. Fix may not be included in next release. type: bug Error or flaw in code with unintended results or allowing sub-optimal usage patterns.
Projects
None yet
Development

No branches or pull requests

2 participants