Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CRITICAL Security Vulnerability #2506

Open
suleyman-ableto opened this issue Jan 9, 2024 · 0 comments
Open

CRITICAL Security Vulnerability #2506

suleyman-ableto opened this issue Jan 9, 2024 · 0 comments

Comments

@suleyman-ableto
Copy link

suleyman-ableto commented Jan 9, 2024

Expected Behavior

Shouldn't have any vulnerabilities on any of the package or dependencies.

Actual Behavior

Our latest scan report shows that contentful-cli has a critical vulnerability. The vulnerability is CVE-2021-44906. The severity is critical. The resource Installed is json5 1.0.2. Full path of the resource is /usr/lib/node_modules/contentful-cli/node_modules/json5. Fixed version is 2.2.1 or above.

Possible Solution

Upgrade package json5 to version 2.2.1 or above.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant