Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Vulnerability in fast-xml-parser #336

Closed
zenonc3 opened this issue Feb 22, 2023 · 1 comment · Fixed by #344
Closed

Vulnerability in fast-xml-parser #336

zenonc3 opened this issue Feb 22, 2023 · 1 comment · Fixed by #344

Comments

@zenonc3
Copy link

zenonc3 commented Feb 22, 2023

Hello!

It looks like webdav-client depends on the 3.y.z version of fast-xml-parser in it's dependencies. However there has recently been a prototype pollution vulnerability that is being lighting up in scanning tools like Snyk and NexusIQ (https://security.snyk.io/vuln/SNYK-JS-FASTXMLPARSER-3325616).

It looks like this vulnerability has been fixed in 4.1.2+ fast-xml-parser as per https://security.snyk.io/package/npm/fast-xml-parser/4.1.2

Do you think it would be possible to upgrade the version of fast-xml-parser being used so this security gap can closed out?

Thanks :)

@perry-mitchell
Copy link
Owner

Fixed in 5.2.0

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants