Skip to content

Request dependency <=2.68 opens to potential memory exposure vulnerability #10352

@evilaliv3

Description

@evilaliv3

Do you want to request a feature or report a bug?
This ticket is to report a a potential security vulnerability caused by the request dependency.

What is the current behavior?
Various of the dependencies used by angular.js make use of a vulnerable version of the request package (<2.68) that allow potential memory exposure.

Involved dependencies are: insight, fsevents

details:

In order to address a short term fix it is suggested to modify the current npm shrinkwrap to use request==2.74.0

Metadata

Metadata

Assignees

No one assigned

    Labels

    area: coreIssues related to the framework runtimefreq2: mediumsecurityIssues that generally impact framework or application securitytype: bug/fix

    Type

    No type

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions