Open tapasthakkar opened 3 years ago
The same CVE (https://nvd.nist.gov/vuln/detail/CVE-2021-23440) has come up in our team discussions as well. If there is an eventual fix for this to remove the vulnerable package then that would certainly be appreciated.
Hi
Issue Description
I noticed that a vulnerability is introduced in forever-monitor@3.0.3: Vulnerability CVE-2021-23440, BDSA-2019-4362 in package set-value (version < 4.0.1): https://nvd.nist.gov/vuln/detail/CVE-2021-23440
The above vulnerable package is referenced by forever-monitor@3.0.3 via:
If forever-monitor@3.0.* removes the vulnerable package from the above version, then its fixed version can help downstream users decrease their pain. Given the large number of downstream users, could you help update your package to remove the vulnerability from forever-monitor?
Thank you.