-
Notifications
You must be signed in to change notification settings - Fork 343
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Update fstream to a secure version #125
Comments
Is this project alive? |
@divanishyn, it doesn't appear to be maintained. Could be time to fork and have a maintained alternative. |
A drop in replacement that is actively maintained can be found here: https://www.npmjs.com/package/unzipper |
I used this package in my project and there are no more security vulnerabilities. |
@ZJONSSON @tanmayghosh2507 @TomasBarry thanks, unzipper works just fine! |
fstream
has a vulnerability in versions lower than1.0.12
.Remediation:
Upgrade fstream to version 1.0.12 or later. For example:
WS-2019-0100
Vulnerable versions: < 1.0.12
Patched version: 1.0.12
Versions of
fstream
prior to 1.0.12 are vulnerable to Arbitrary File Overwrite.The text was updated successfully, but these errors were encountered: