Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2022-46175 - High #252

Open
ldco2016 opened this issue Jan 4, 2024 · 1 comment
Open

CVE-2022-46175 - High #252

ldco2016 opened this issue Jan 4, 2024 · 1 comment

Comments

@ldco2016
Copy link

ldco2016 commented Jan 4, 2024

Guys, we are using a dependency called svg-inline-loader which is using loader-utils@.4.2 which seems to be using json5@1.0.2 and since svg-inline-loader version we are using is the latest one, we would need for loader-utils to be on a version that is using a json5 version where the CVE has been patched or perhaps a version not needing that dependency at all.

Could you please advise as we need to resolve these vulnerabilities as soon as possible.

@alexander-akait
Copy link
Member

loader-utils is deprecated and should not used in loader anymore, also loader-utils@0.4.2 is outdated and this CVE was fixed in the last version, so please ask developer(s) of svg-inline-loader update deps

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants