Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Urgent matter #1

Closed
Cyber-Dude1 opened this issue Apr 22, 2021 · 8 comments
Closed

Urgent matter #1

Cyber-Dude1 opened this issue Apr 22, 2021 · 8 comments

Comments

@Cyber-Dude1
Copy link

Cyber-Dude1 commented Apr 22, 2021

Hi there,
Can you please contact me by mail?

Thanks.

@Cyber-Dude1 Cyber-Dude1 changed the title Prototype Pollution in Mixme Urgent matter Apr 22, 2021
@Cyber-Dude1 Cyber-Dude1 reopened this Apr 22, 2021
wdavidw added a commit that referenced this issue Apr 25, 2021
@wdavidw
Copy link
Member

wdavidw commented Apr 25, 2021

Thank you @Cyber-Dude1 for reporting this vulnerability. Version 0.5.1 fixes this issue.

@wdavidw wdavidw closed this as completed Apr 25, 2021
@Cyber-Dude1
Copy link
Author

Cyber-Dude1 commented Apr 26, 2021 via email

@wdavidw
Copy link
Member

wdavidw commented Apr 26, 2021 via email

@Cyber-Dude1
Copy link
Author

Cyber-Dude1 commented Apr 26, 2021 via email

@wdavidw
Copy link
Member

wdavidw commented Apr 26, 2021 via email

@Cyber-Dude1
Copy link
Author

Cyber-Dude1 commented May 5, 2021

Hi David,
Sorry for the late reply..
So, the best way of doing so is to create a security advisory for this repo (in GitHub). Once it will be submitted, NPM team will review.
You can follow the steps described here.

Thanks :)

@Cyber-Dude1
Copy link
Author

Hi David,
Please notice that CVE-2021-28860 got assigned for this vulnerability.

@wdavidw
Copy link
Member

wdavidw commented May 5, 2021

Yes, I got the notification. My understanding is that the NPM team will get notified and take further actions without the need to contact them.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants