Skip to content

Prototype Pollution vuln due to unset-value sub-dep < 2.0.1 #5725

@olozzalap

Description

@olozzalap

Is there an existing issue for this?

How do you use Sentry?

Sentry Saas (sentry.io)

Which package are you using?

@sentry/nextjs

SDK Version

7.12.1

Framework Version

7.12.1

Link to Sentry event

No response

Steps to Reproduce

  1. Install the latest "@sentry/nextjs": "7.12.1"
  2. Validate with Snyk or similar security vulnerability tool
  3. See affecting Prototype Pollution security vulnerability bug from "unset-value": "<2.0.1" sub-dep. It is part of @sentry/nextjs via: @sentry/nextjs@7.12.1 › jscodeshift@0.13.1 › micromatch@3.1.10 › braces@2.3.2 › snapdragon@0.8.2 › base@0.11.2 › cache-base@1.0.1 › unset-value@1.0.0

References:

Expected Result

No security vulnerabilities from @sentry/nextjs

Actual Result

See affecting Prototype Pollution security vulnerability bug from "unset-value": "<2.0.1" sub-dep. It is part of @sentry/nextjs via: @sentry/nextjs@7.12.1 › jscodeshift@0.13.1 › micromatch@3.1.10 › braces@2.3.2 › snapdragon@0.8.2 › base@0.11.2 › cache-base@1.0.1 › unset-value@1.0.0

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions