loopbackio / loopbackio/loopback-connector

CVE-2021-21368 msgpack5 4.5.1 is vulnerable, need to update to 6.0.2

Open
#650 2 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

bug
Dominant language
JavaScript
Stars
35
Forks
102
Avg merge
14h 26m
Merged PRs (30d)
13

Description

(https://nvd.nist.gov/vuln/detail/CVE-2021-21368)

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by locating the dependency declaration for msgpack5 and compare the current 4.5.1 version with the requested 6.0.2 update. Review the linked CVE-2021-21368 details, then confirm the dependency and any lockfile no longer select the vulnerable version.

Written by the indexing model from the issue text.

Assessment

Tech stack
javascript
Domain
security
Issue type
Bug
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.