You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Do you want to request a feature, report a bug or ask a question?
I have a dependabot alert :
CVE-2021-23440
high severity
Vulnerable versions: < 4.0.1
Patched version: 4.0.1
This affects the package set-value before 4.0.1. A type confusion vulnerability can lead to a bypass of CVE-2019-10747 when the user-provided keys used in the path parameter are arrays.
The latest possible version that can be installed is 2.0.1 because of the following conflicting dependencies:
[email protected] requires set-value@^2.0.0 via a transitive dependency on [email protected][email protected] requires set-value@^2.0.1 via a transitive dependency on [email protected]
The earliest fixed version is 4.0.1.
Please tell us about your environment:
svg-sprite-loader version: 6.0.9
The text was updated successfully, but these errors were encountered:
Do you want to request a feature, report a bug or ask a question?
I have a dependabot alert :
Please tell us about your environment:
The text was updated successfully, but these errors were encountered: