luwes / craft-codemirror

Add the awesome in-browser code editor CodeMirror as a field type.
MIT License
18 stars 10 forks source link

VeraCode scan security issue #15

Open pvaessen opened 3 years ago

pvaessen commented 3 years ago

Hi,

We are using the craft3-codemirror plug-in for Craft CMS 3.5.13.2 and a recent VeraCode security scan came up with a medium security flaw for this plug-in.

The issue is reported on line 686 for /src/assets/addon/tern/tern.js

For more details: https://cwe.mitre.org/data/definitions/117.html

Can this be fixed ?