Skip to content

High security vulnerability with dependent library - underscore < 1.12.1 #1639

Open
@madhurinamagiri

Description

@madhurinamagiri

Hi Team,

An older version of the dependent library is being used. Which has the "Arbitrary Code Execution" vulnerability.

upgrading the library will do the fix. Here is the report of the npm audit.

High Arbitrary Code Execution

Package underscore

Patched in >=1.12.1

Dependency of react-bootstrap-table-next

Path react-bootstrap-table-next > underscore

As we are using this library for production purposes, due to security issues we are blocked. A quick path will do the needful.

Thanks!!

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions