Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

yargs-parser vulnerability #2559

Closed
1 of 2 tasks
nessor opened this issue May 1, 2020 · 2 comments · Fixed by #2566
Closed
1 of 2 tasks

yargs-parser vulnerability #2559

nessor opened this issue May 1, 2020 · 2 comments · Fixed by #2566

Comments

@nessor
Copy link

nessor commented May 1, 2020

  • Node Version: 12.16.1

  • NPM Version: 6.13.4

  • OS: Ubuntu 19.10

  • This is a bug

  • This is a modification request

Hey guys,

npm is reporting a Prototype Pollution vulnerability on the yargs-parser dependency

Low Prototype Pollution
Package yargs-parser
Patched in >=13.1.2 <14.0.0 || >=15.0.1 <16.0.0 || >=18.1.2
Dependency of webpack-dev-server [dev]
Path webpack-dev-server > yargs > yargs-parser
More info https://npmjs.com/advisories/1500

@panuhorsmalahti
Copy link

panuhorsmalahti commented May 4, 2020

Fix should be to update the yargs dependency.

@gbhasha
Copy link

gbhasha commented May 6, 2020

Snyk Report: https://snyk.io/test/npm/webpack-dev-server

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

3 participants