mscdex / node-imap

An IMAP client module for node.js.
MIT License
2.14k stars 379 forks source link

Twistlock finds semver CVE-2022-25883 (M) #905

Open praveendiwakar1 opened 10 months ago

praveendiwakar1 commented 10 months ago

Hi team , there is a security vulnerability in semverpackage being consumed via ututf7@1.0.2 as below,


`-- imap@0.8.19
    `-- utf7@1.0.2
      `-- semver@5.3.0

As there is no repo for utf7,and we are consuming the semverfrom imap. Please pinned the semver 7.5.4to resolve the issue.