DEFRA / defra-identity-hapi-plugin

Hapi plugin to standardise the way Defra services interact with an OpenID Connect Identity Provider
Other
0 stars 6 forks source link

Use of adal-node@0.1.28 is security risk #98

Open Ibabalola opened 3 years ago

Ibabalola commented 3 years ago

It has been reported that adal-node@0.1.28 has a Low security risk which seems to have been resolved in the lastest version of the package @0.2.2

                       === npm audit security report ===                        

# Run  npm update xmldom --depth 3  to resolve 1 vulnerability
┌───────────────┬──────────────────────────────────────────────────────────────┐
│ Low           │ Misinterpretation of malicious XML input                     │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Package       │ xmldom                                                       │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Dependency of │ @envage/defra-identity-hapi-plugin                           │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ Path          │ @envage/defra-identity-hapi-plugin > adal-node > xmldom      │
├───────────────┼──────────────────────────────────────────────────────────────┤
│ More info     │ https://npmjs.com/advisories/1650                            │
└───────────────┴──────────────────────────────────────────────────────────────┘