Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2024-39249 reported for async-3.2.5 #1977

Closed
wanghwh opened this issue Jul 11, 2024 · 1 comment
Closed

CVE-2024-39249 reported for async-3.2.5 #1977

wanghwh opened this issue Jul 11, 2024 · 1 comment
Labels

Comments

@wanghwh
Copy link

wanghwh commented Jul 11, 2024

What version of async are you using?
3.2.5
Which environment did the issue occur in (Node/browser/Babel/Typescript version)
Node

What did you do? Please include a minimal reproducible case illustrating issue.
development using winston , which depends on async

What did you expect to happen?
Remediate this CVE https://nvd.nist.gov/vuln/detail/CVE-2024-39249

What was the actual result?
Vulnerability reported by WhiteSource Security Check during our build pipeline

@aearly
Copy link
Collaborator

aearly commented Jul 11, 2024

Dupe of #1975

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

2 participants