Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[GHSA-m2h2-264f-f486] angular vulnerable to regular expression denial of service (ReDoS) #5076

Conversation

lennin-cp
Copy link

Updates

  • Affected products

Comments
The issue is fixed in HeroDevs version 1.9.7.

@github-actions github-actions bot changed the base branch from main to lennin-cp/advisory-improvement-5076 December 11, 2024 22:16
@darakian
Copy link
Contributor

Hey @lennin-cp, similar to #5075 the version your suggesting doesn't seem to exist https://www.npmjs.com/package/angular/v/1.9.7

@lennin-cp
Copy link
Author

@darakian, thank you for the follow-up on this. The fix is not in a community version but a paid version offered by HeroDevs, see https://docs.herodevs.com/angularjs/faqs/fixed-vuln

@darakian
Copy link
Contributor

same as with #5075
our scope is strictly limited to public packages on public registries.
https://github.com/github/advisory-database?tab=readme-ov-file#supported-ecosystems
We cannot inspect nor recommend private packages.

@darakian darakian closed this Dec 12, 2024
@github-actions github-actions bot deleted the lennin-cp-GHSA-m2h2-264f-f486 branch December 12, 2024 17:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants