-
Notifications
You must be signed in to change notification settings - Fork 149
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Security Issue in Dependency - CVE-2022-24434 #800
Comments
@jamhall this is quite a serious vulnerability. Are we able to have this resolved? If I make a PR will you merge it? |
I also think this is a pretty serious vulnerability. @jpike88, did you manage to solve it? If not, then it would definitely be a help for all other developers. I would also help, but I don't have enough time to find out for myself. |
I don’t think the maintainer is very interested in maintaining this, look how many PRs are open and unaddressed. Best thing to do is just fork it |
hello @jpike88, it was similar last year until "jamhall" released a new version. Somewhere it was said that a version 4.0 should follow, but not when. We can ask @leontastic if he is in contact with @jamhall and if it makes sense to open a PR here. But if I were you, I would open a PR here, then all developers can help, and the result is useful for everyone. But your decision. Let me know and I'll help. |
NPM audit, and other security vulnerability scanning tools, are indicating the following issue in version 3.7.1 of s3rver:
My understanding is the issue (GHSA-wm7h-9275-46v2) was addressed in busboy v1.0.0 (mscdex/busboy#250 (comment)). Could a new version of s3rver be released that uses a newer version of busboy to address this issue?
The text was updated successfully, but these errors were encountered: