Skip to content
This repository has been archived by the owner on Feb 13, 2024. It is now read-only.

Bumped axios version to patch ReDoS vulnerability #295

Merged
merged 1 commit into from
Sep 8, 2021

Conversation

Dahaden
Copy link
Contributor

@Dahaden Dahaden commented Sep 7, 2021

Vulnerability: https://www.huntr.dev/bounties/1e8f07fc-c384-4ff9-8498-0690de2e8c31/

Vulnerability fix: axios/axios#3980

Axios Releases: https://github.com/axios/axios/releases

In versions 0.19.1-0.21.1, there is an exploit to trigger a ReDoS attack.
The versions in the package.json are good enough to allow people to manually bump to a fixed version, but also good to prevent this in the first place :)

@pooyaj pooyaj self-requested a review September 8, 2021 17:41
@pooyaj pooyaj merged commit c41bac7 into segmentio:master Sep 8, 2021
@Dahaden
Copy link
Contributor Author

Dahaden commented Sep 13, 2021

Hey @pooyaj Thanks for merging this in so quick! Any chance I could get a release of master? I now have two PRs awaiting a release :)

Thanks again!

@pooyaj
Copy link
Contributor

pooyaj commented Sep 13, 2021

@Dahaden Released 5.1.0 🎉 and thanks for all the PRs 🙌

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants