Azure / azure-iot-sdk-node

A Node.js SDK for connecting devices to Microsoft Azure IoT services
https://docs.microsoft.com/en-us/azure/iot-hub/
Other
261 stars 226 forks source link

azure-iot-provisioning-device-amqp #1218

Open kasasusmitha12 opened 3 months ago

kasasusmitha12 commented 3 months ago

We need to upgrade this version "0.10.64" . We have found a vulnerability in the ES5 package. Please consider upgrading and releasing new release notes for the package. Here i am providing CVE and vendor Advisories . CVE: https://nvd.nist.gov/vuln/detail/CVE-2024-27088 Vendor Advisories : https://github.com/medikoo/es5-ext/security/advisories/GHSA-4gmj-3p3h-gm8h https://github.com/medikoo/es5-ext/commit/a52e95736690ad1d465ebcd9791d54570e294602 https://github.com/medikoo/es5-ext/commit/3551cdd7b2db08b1632841f819d008757d28e8e2 https://github.com/medikoo/es5-ext/releases/tag/v0.10.63 https://github.com/medikoo/es5-ext/issues/201