You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Our customer reported a vulnerability in bluemix-autoscaling-agent caused by "request" package.
The vulnerability reports that
"The request package is vulnerable to Weak Authentication Algorithm. The function function in oauth.js uses SHA-1 for authentication which is no longer considered cryptographically secure."
Here is the hierarchy of the "request" module tracking back to appmetrics
According to request/request#2640 it looks like all versions of request are vulnerable and the request package is depreciated.
Can you please take a look? thanks,
The text was updated successfully, but these errors were encountered:
Our customer reported a vulnerability in bluemix-autoscaling-agent caused by "request" package.
The vulnerability reports that
Here is the hierarchy of the "request" module tracking back to appmetrics
"request"
-->kubernetes-client"
-->"ibmapm-restclient"
-->"ibmapm-embed"
-->"appmetrics"
-->bluemix-autoscaling-agent
According to request/request#2640 it looks like all versions of request are vulnerable and the request package is depreciated.
Can you please take a look? thanks,
The text was updated successfully, but these errors were encountered: