Skip to content

Prototype pollution vulnerability in jszip@2.5.x #655

Description

@s100

appmetrics depends on jszip@2.5.x, which has this prototype pollution vulnerability in it. Suggested remediation is to upgrade to jszip@3.7.0 or later.

Here is the upgrade guide for upgrading from jszip 2 to 3.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Fields

    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions