Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix(security): address CVE-2022-25881 #2718

Closed
aldousalvarez opened this issue Sep 22, 2023 · 1 comment
Closed

fix(security): address CVE-2022-25881 #2718

aldousalvarez opened this issue Sep 22, 2023 · 1 comment
Assignees

Comments

@aldousalvarez
Copy link
Contributor

aldousalvarez commented Sep 22, 2023

Based on the latest trivy vulnerability scan here. There is one remaining vulnerability that needs to be fixed on carbon-accounting-backend after using the version @2.0.0-alpha.1.

http-cache-semantics (package.json)
Regular Expression Denial of Service (ReDoS) vulnerability|
https://avd.aquasec.com/nvd/cve-2022-25881
Package: carbon-accounting-backend
Installed Version: 4.1.0
Fixed Version: 4.1.1

aldousalvarez added a commit to aldousalvarez/cactus that referenced this issue Sep 22, 2023
Fixes hyperledger-cacti#2718

[ci skip]
Signed-off-by: aldousalvarez <aldousss.alvarez@gmail.com>
@jagpreetsinghsasan
Copy link
Contributor

Fixed by the PR #3146

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants