richardgirges / express-fileupload

Simple express file upload middleware that wraps around busboy
MIT License
1.52k stars 261 forks source link

Security Vulnerabilities #313

Closed guy-microsoft closed 2 years ago

guy-microsoft commented 2 years ago

There are 2 security vulnerabilities without an available fix: Vulnerability 1 Vulnerability 2

guy-microsoft commented 2 years ago

Any updates @richardgirges ? The issue hasn't been fixed and has been surfaced here as well: https://www.whitesourcesoftware.com/vulnerability-database/CVE-2022-27140

richardgirges commented 2 years ago

Feel free to send a PR

richardgirges commented 2 years ago

Closing in favor of #312