-
Notifications
You must be signed in to change notification settings - Fork 853
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
micromatch vulnerable at v4.0.5 #1004
Comments
Thanks for the report. To get some facts right: Please follow threads in
A fix has landed in
Suggestion is to monitor the upstream progress. |
There is NO vulnerability: micromatch/braces#37 (comment) |
To resolve the issue, update your package |
Describe the feature you'd love to see
https://github.com/chimurai/http-proxy-middleware/blob/master/package.json#L93
micromatch
is vulnerable at v4.0.5 as per https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-4067. To me, it doesn't look like they are going to cut a new release -- their last commit was in 2019.So this is a feature request to move to a different matching package -- one that is maintained more regularly or at least isn't vulnerable to this CVE.
Additional context (optional)
No response
The text was updated successfully, but these errors were encountered: