Uncaught Exception in yaml #27

Closed
opened 2023-04-25 04:46:13 +00:00 by argoyle · 0 comments
argoyle commented 2023-04-25 04:46:13 +00:00 (Migrated from gitlab.com)

⚠️ dependabot-gitlab has detected security vulnerability for yaml in path: /, manifest_file: /package.json but was unable to update it! ⚠️

Package Severity Affected versions Patched versions IDs
yaml (NPM) MODERATE < 2.2.2 2.2.2 GHSA-f9xv-q969-pqx4,CVE-2023-2251

Description

Uncaught Exception in GitHub repository eemeli/yaml prior to 2.2.2.

References

⚠️ `dependabot-gitlab` has detected security vulnerability for `yaml` in path: `/`, manifest_file: `/package.json` but was unable to update it! ⚠️ * https://github.com/advisories/GHSA-f9xv-q969-pqx4 | Package | Severity | Affected versions | Patched versions | IDs | |------------|----------|-------------------|------------------|---------------------------------------| | yaml (NPM) | MODERATE | < 2.2.2 | 2.2.2 | `GHSA-f9xv-q969-pqx4`,`CVE-2023-2251` | # Description Uncaught Exception in GitHub repository eemeli/yaml prior to 2.2.2. # References * https://nvd.nist.gov/vuln/detail/CVE-2023-2251 * https://github.com/eemeli/yaml/commit/984f5781ffd807e58cad3b5c8da1f940dab75fba * https://huntr.dev/bounties/4b494e99-5a3e-40d9-8678-277f3060e96c * https://github.com/advisories/GHSA-f9xv-q969-pqx4
argoyle (Migrated from gitlab.com) closed this issue 2023-06-02 14:11:19 +00:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: dancefinder/dancefinder-app#27