microsoft / ApplicationInsights-node.js

Microsoft Application Insights SDK for Node.js
MIT License
324 stars 141 forks source link

Dependency xml2js < 0.5.0 high vulnerability (Prototype pollution) #1122

Closed thayarasiqueira closed 1 year ago

thayarasiqueira commented 1 year ago

The xml2js dependency used by applicationinsights needs to be updated to the latest version, updated 3 days ago, which corrects the vulnerability issue found on the previous versions.

https://www.npmjs.com/package/xml2js?activeTab=versions https://security.snyk.io/vuln/SNYK-JS-XML2JS-5414874