-
-
Notifications
You must be signed in to change notification settings - Fork 644
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Security vulnerabilities found in dependency YUI #434
Comments
jsrsasign uses very small part of YUI. Just object inheritance class definition. So those vulnerability are not affect to jsrsasign. Part of YUI code is planed to remove from jsrsasign in the future. Thank you. |
Good to hear that. |
Hi @kjur The problem isn't only which part of YUI that is being used by jsrasign. So please reconsider removing or updating this dependency as quickly as possible. |
YUI 2.9.0 has known vulnerabilities:
severity: high; CVE: CVE-2012-5883; http://www.cvedetails.com/cve/CVE-2012-5883/
severity: high; CVE: CVE-2012-5882; http://www.cvedetails.com/cve/CVE-2012-5882/
severity: high; CVE: CVE-2012-5881; http://www.cvedetails.com/cve/CVE-2012-5881/
The text was updated successfully, but these errors were encountered: