react-bootstrap-table / react-bootstrap-table2

Next Generation of react-bootstrap-table
https://react-bootstrap-table.github.io/react-bootstrap-table2/
MIT License
1.27k stars 431 forks source link

Dependency Underscore -1.9.1 has CRITICAL Vulnerability - Arbitrary Code Execution in underscore which has patched in >=1.12.1 versions of underscore #1817

Open Shobha-Potti opened 7 months ago

Shobha-Potti commented 7 months ago

when I use this package react-bootstrap-table-next in create-react-app project.

when checking for vulnerabilities in the terminal

npm audit

I am encountering this error

┌───────────────┬──────────────────────────────────────────────────────────────┐ │ Critical │ Arbitrary Code Execution in underscore │ ├───────────────┼──────────────────────────────────────────────────────────────┤ │ Package │ underscore │ ├───────────────┼──────────────────────────────────────────────────────────────┤ │ Patched in │ >=1.12.1 │ ├───────────────┼──────────────────────────────────────────────────────────────┤ │ Dependency of │ react-bootstrap-table-next │ ├───────────────┼──────────────────────────────────────────────────────────────┤ │ Path │ react-bootstrap-table-next > underscore │ ├───────────────┼──────────────────────────────────────────────────────────────┤ │ More info │ https://github.com/advisories/GHSA-cf4h-3jhx-xvhq ├───────────────┼───────────────────────────────────────