Done
Details
Assignee
Mike TaylorMike TaylorReporter
Julian LadischJulian LadischLabels
Priority
TBDDevelopment Team
ThorTestRail: Cases
Open TestRail: CasesTestRail: Runs
Open TestRail: Runs
Details
Details
Assignee
Mike Taylor
Mike TaylorReporter
Julian Ladisch
Julian LadischLabels
Priority
Development Team
Thor
TestRail: Cases
Open TestRail: Cases
TestRail: Runs
Open TestRail: Runs
Created November 30, 2021 at 10:09 PM
Updated February 28, 2022 at 12:30 PM
Resolved December 1, 2021 at 12:44 PM
json-ptr < 3.0.0 has a prototype pollution security vulnerability: https://nvd.nist.gov/vuln/detail/CVE-2021-23509
Dependency path:
raml-1-parser@1.1.47
requiresjson-path@0.1.3
requiresjson-ptr@~0.1.1
json-ptr@~0.1.1
is resolved tojson-ptr 2.2.0
: https://github.com/folio-org/mod-graphql/blob/ee78059a28d2cc7c7e92aa4dcdbc5fb249d4b094/yarn.lock#L4390-L4391json-path
has not been maintained since 2013: https://www.npmjs.com/package/json-pathTherefore we need to bump the json-ptr version via the "resolutions" section of package.json.