Closed jcreamer898 closed 1 year ago
There is a downstream CVE in xml2js 0.4.23.
https://sechead.com/headlines/cve:ef1ef9c462db44ee1afdf8a79418bdacafa9447ae8d64927cb278f4f3673072c
Bumping the storage-blob package will fix it by ensuring it uses 0.5.0 of xml2js.
I ended up doing this update and the Node version bump in separate PRs. New version should be released shortly.
There is a downstream CVE in xml2js 0.4.23.
https://sechead.com/headlines/cve:ef1ef9c462db44ee1afdf8a79418bdacafa9447ae8d64927cb278f4f3673072c
Bumping the storage-blob package will fix it by ensuring it uses 0.5.0 of xml2js.