chill117 / express-mysql-session

A MySQL session store for the express framework in node
MIT License
313 stars 109 forks source link

update underscore to fix CVE-2021-23358 #121

Closed sseide closed 3 years ago

sseide commented 3 years ago

This one updates underscore from 1.12.0 to latest bugfix release 1.12.1 to fix an Arbitrary Code Execution vulnerability (rated high so far).

Please release a new version of your package too to allow all others to pickup this changes as you use explicit version pinning.

Thanks, S. Seide