Skip to content

Vulnerable class-validator with CVE-2019-18413 being pulled in, mitigations may need to be applied ! #880

Description

@yahanvesh

Summary

Based on the discussion typestack/class-validator#438, currently there is no fixed version of class-validator which fixes the CVE-2019-18413.
However a mitigation is suggested at typestack/class-validator#438 (comment) about the use of a previously undocumented option.

Expected Behavior

Respective changes as needed to be made to use the mitigations suggested at typestack/class-validator#438 (comment)

Current Behavior

Currently the latest version of javascript-obfuscator pulls in class-validator which has a vulnerable CVE.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions