2 Medium Severity Vulnerabilities found by Snyk (dot-prop)
See original GitHub issueSummary
Snyk has found the following issues:
Issues to fix by upgrading:
Upgrade configstore@3.1.2 to configstore@5.0.0 to fix
✗ Prototype Pollution [Medium Severity][https://snyk.io/vuln/SNYK-JS-DOTPROP-543489] in dot-prop@4.1.1
introduced by configstore@3.1.2 > dot-prop@4.1.1 and 1 other path(s)
Upgrade update-notifier@2.5.0 to update-notifier@4.0.0 to fix
✗ Prototype Pollution [Medium Severity][https://snyk.io/vuln/SNYK-JS-DOTPROP-543489] in dot-prop@4.1.1
introduced by configstore@3.1.2 > dot-prop@4.1.1 and 1 other path(s)
Issue Analytics
- State:
- Created 4 years ago
- Comments:5
Top Results From Across the Web
Code injection vulnerabilities (CVSSv3 5.8) found in Snyk CLI ...
As a Snyk user, we want to let you know about two new medium severity (CVSSv3 5.8) vulnerabilities in our CLI and IDE...
Read more >dot-prop - Snyk Vulnerability Database
version published direct vulnerabilities
7.2.0 16 Feb, 2022 0. C. 0. H. 0. M. 0. L
7.1.1 22 Jan, 2022 0. C. 0. H. 0....
Read more >google-translate-api@2.0.3 vulnerabilities - Snyk
Find, fix and prevent vulnerabilities in your code. ... Severity. Critical. High. Medium. 2. Low. Status. Open. 2. Patched. 0. Ignored. 0. medium...
Read more >Severity levels - Snyk User Docs
A severity level is applied to a vulnerability, to indicate the risk for that vulnerability in an application.
Read more >Command injection vulnerability in Snyk CLI released prior to ...
As a Snyk user, we want to let you know about a medium severity ... You can find the individual vulnerabilities in our...
Read more >Top Related Medium Post
No results found
Top Related StackOverflow Question
No results found
Troubleshoot Live Code
Lightrun enables developers to add logs, metrics and snapshots to live code - no restarts or redeploys required.
Start FreeTop Related Reddit Thread
No results found
Top Related Hackernoon Post
No results found
Top Related Tweet
No results found
Top Related Dev.to Post
No results found
Top Related Hashnode Post
No results found
Top GitHub Comments
I did scope out our CI audit step to exclude developer dependencies to calm it down but probably worth knowing they have you on the naughty list 😉
yarn audit is flagging this as high severity