Dependency node-forge has critical security vulnerability
csvan opened this issue · 2 comments
csvan commented
node-forge 0.10.0
Severity: critical
node-forge Package for Node.js lib/debug.js set() Function Prototype Pollution Unspecified Issue - 418sec/forge#1
davidlehn commented
This issue is fixed in node-forge 1.0.0.
(I doubt anyone has ever used that debug API, including forge itself, so it's probably not "critical".)
csvan commented
Yea I think the classifications are weird sometimes too :-/