flash-oss / node_acl

Access control lists for node applications
MIT License
63 stars 9 forks source link

Vulnerability to prototype pollution in async #9

Closed tutyamxx closed 2 years ago

tutyamxx commented 2 years ago

https://github.com/advisories/GHSA-fwr7-v2mv-hh25

koresar commented 2 years ago

Fixed. Published as v3.0.1

tutyamxx commented 2 years ago

Thank you kindly. Please make sure you publish it to npm (if you don't have the automatic package publisher set up). Thanks again.

koresar commented 2 years ago

Mate. Take a look a my message above. Does it answer your question?

tutyamxx commented 2 years ago

I did, apologies the npm page was cached and still showed last update 4 months ago. I forced a reload and it updated. Apologies for any inconveniences.