Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security Vulnerability - loader-utils 2.0.2 #679

Closed
rodoabad opened this issue Oct 18, 2022 · 6 comments
Closed

Security Vulnerability - loader-utils 2.0.2 #679

rodoabad opened this issue Oct 18, 2022 · 6 comments

Comments

@rodoabad
Copy link

rodoabad commented Oct 18, 2022

Screenshot 2022-10-18 at 11 12 05 AM

@pmmmwh a lock rebuild should fix this or us updating ^2.0.0 to the latest v3 version.

https://www.mend.io/vulnerability-database/CVE-2022-37599

@hnjoshi
Copy link

hnjoshi commented Oct 27, 2022

+1
I am seeing the same vulnerability in scan. It will be very helpful if loader-utils is updated to v3.

@pmmmwh
Copy link
Owner

pmmmwh commented Oct 29, 2022

To my understanding, it is possible to update to loader-utils@2.0.3 which fixes this CVE without having us update to v3. That should be possible once you do a lockfile rebuild.

@gouthamr22
Copy link

+1
I am seeing the same issue could you update it to loader-utils - 3.0.0

@hnjoshi
Copy link

hnjoshi commented Oct 31, 2022

@pmmmwh currently npm install is not fetching 2.0.3 loader-utils. So can you please help update the loader-utils in your pkg json so that we can get updated version?

@pbochnak
Copy link

pbochnak commented Nov 8, 2022

Hi Guys, when can we expect a release with updated loader-utils?

@pmmmwh
Copy link
Owner

pmmmwh commented Nov 10, 2022

Fixed by #685

@pmmmwh pmmmwh closed this as completed Nov 10, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

5 participants