Skip to content
This repository has been archived by the owner on Aug 4, 2023. It is now read-only.

Vulnerability in dicer package #640

Open
TheBrockEllis opened this issue Aug 3, 2022 · 1 comment
Open

Vulnerability in dicer package #640

TheBrockEllis opened this issue Aug 3, 2022 · 1 comment

Comments

@TheBrockEllis
Copy link

According to NPM audit, the dicer package has been marked with a high vulnerability. Swagger-tools is impacted by this vulnerability by way of this path: swagger-tools > multer > busboy > dicer

CVE link:GHSA-wm7h-9275-46v2

The multer team has just recently updated their 1.x branch to include a fix in a backwards compatible way. The branch can be found here.

Is there any chance that swagger-tools could be updated to use v1.4.5-lts.1 of multer? Would be will to put together the PR if desirable.

@leachjustin18
Copy link

Any updates on this?

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants