deptofdefense / dds.mil

The website of the Defense Digital Service.
https://dds.mil
MIT License
19 stars 15 forks source link

Patched 🐛 CVE-2020-28502 #451

Open imhunterand opened 1 year ago

imhunterand commented 1 year ago

This affects the package xmlhttprequest before 1.7.0; all versions of package xmlhttprequest-ssl. Provided requests are sent synchronously (async=False on xhr.open), malicious user input flowing into xhr.send could result in arbitrary code being injected and run.

Severity High
GHSA-h4j5-c7cj-74xg

netlify[bot] commented 1 year ago

Deploy Preview for dds-mil ready!

Name Link
Latest commit 2f0ce8e1b6baa3512f4dace1a9364e4072e014d1
Latest deploy log https://app.netlify.com/sites/dds-mil/deploys/62fb6d3178073700091db6e9
Deploy Preview https://deploy-preview-451--dds-mil.netlify.app
Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify site settings.