Autodesk / Autodesk/hig

There is a vulnerability in node-forge 0.7.5,upgrade recommended

Open
#2,499 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
JavaScript
Stars
193
Forks
112
PR merge metrics
No merged PRs in 30d

Description

https://github.com/Autodesk/hig/blob/80680833679c324da5bb36cfe74f36c15c9672bc/acceptance/yarn.lock#L7188-L7190

CVE-2020-7720

Recommended upgrade version:0.10.0

Contributor guide

Open the contributing guide

Research direction

Inspect acceptance/yarn.lock at lines 7188-7190, where node-forge 0.7.5 is recorded. Update the dependency to 0.10.0 and verify the lockfile no longer pins the vulnerable version associated with CVE-2020-7720.

Written by the indexing model from the issue text.

Assessment

Tech stack
javascript
Domain
security
Issue type
Bug
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Stale
Clarity
Clearly specified
Newbie friendliness
55/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.