Skip to content

Conversation

@musculman
Copy link
Contributor

@musculman musculman commented Jul 9, 2019

brfs versions lower than 2.0.0 pull in the static-eval version < 2.0.0 that contains a vulnerability.

Other updates are for minor and patch flagged by npm audit

More details about the vulnerability
CVE-2017-16226
Vulnerable versions: < 2.0.0
Patched version: 2.0.0
The static-eval module is intended to evaluate statically-analyzable expressions. In affected versions, untrusted user input is able to access the global function constructor, effectively allowing arbitrary code execution.

@devongovett devongovett merged commit 0e04e01 into foliojs:master Nov 17, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants