-
-
Notifications
You must be signed in to change notification settings - Fork 1.1k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
DoS vulnerability from dicer@0.2.5 #1095
Comments
Better solution: #1097 |
@mrded Thanks for raising this PR 1097. Request the team to merge this soon. As github is also reporting a high vulnerability which will get fixed with this busboy version upgrade. GHSA-wm7h-9275-46v2 |
High Crash in HeaderParser in dicer Package dicer Patched in No patch available Dependency of multer Path multer > busboy > dicer |
We need that fix, i don't like |
I need this |
This is fixed in version |
Thank you it works.
|
What versions of Node are compatible? |
v10.16.0 or newer |
i've upgraded all my projects to 16 lts
…________________________________
From: Linus Unnebäck ***@***.***>
Sent: Thursday, June 16, 2022 10:33
To: expressjs/multer ***@***.***>
Cc: victorKariuki ***@***.***>; Comment ***@***.***>
Subject: Re: [expressjs/multer] DoS vulnerability from ***@***.*** (Issue #1095)
What versions of Node are compatible?
v10.16.0 or newer
—
Reply to this email directly, view it on GitHub<#1095 (comment)>, or unsubscribe<https://github.com/notifications/unsubscribe-auth/ATTZYI52BNNIQIE56WDBTMDVPLKDNANCNFSM5WP4UIOQ>.
You are receiving this because you commented.Message ID: ***@***.***>
|
Has this been done or we should do npm i multer@1.4.5-lts.1? |
@LinusU perhaps a good reason to release it as |
Is any way to resolve this issue? |
@bryanph there is already another @ZhaoKunLong @ashish1497 yes, |
Hello,
Snyk is reporting a vulnerability in this repo, that is coming from the Dicer library:
Updating
busboy@^1.0.0
drops the dependency on dicer (where the vuln comes from).Thanks
The text was updated successfully, but these errors were encountered: