facebookarchive / flux

Application Architecture for Building User Interfaces
https://facebookarchive.github.io/flux/
Other
17.42k stars 3.47k forks source link

CVE-2020-7733 vulnerability by linking to an older fbjs version #505

Closed tjercus closed 3 years ago

tjercus commented 3 years ago

For details see https://www.tenable.com/cve/CVE-2020-7733. The fix would be to upgrade the dependency fbjs to the latest version. That version is not vulnerable.

TomBrien commented 3 years ago

Also found this package as the root cause of a vulnerability to CVE-2020-15168 which would be solved by bumping fbjs

dschaller commented 3 years ago

Fixed in https://github.com/facebook/flux/pull/507