Closed renovate[bot] closed 1 year ago
This PR contains the following updates:
0.4.23
0.5.0
xml2js versions before 0.5.0 allows an external attacker to edit or add new properties to an object. This is possible because the application does not properly validate incoming JSON keys, thus allowing the __proto__ property to be edited.
__proto__
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
â™» Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Mend Renovate. View repository job log here.
This PR contains the following updates:
0.4.23
->0.5.0
GitHub Vulnerability Alerts
CVE-2023-0842
xml2js versions before 0.5.0 allows an external attacker to edit or add new properties to an object. This is possible because the application does not properly validate incoming JSON keys, thus allowing the
__proto__
property to be edited.Release Notes
Leonidas-from-XIV/node-xml2js (xml2js)
### [`v0.5.0`](https://togithub.com/Leonidas-from-XIV/node-xml2js/compare/8fc5b926846cd4ef9a2dbccd411705e0c110a708...0.5.0) [Compare Source](https://togithub.com/Leonidas-from-XIV/node-xml2js/compare/8fc5b926846cd4ef9a2dbccd411705e0c110a708...0.5.0)Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
â™» Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Mend Renovate. View repository job log here.