jfromaniello/selfsigned

Dependency node-forge has critical security vulnerability

csvan opened this issue · 2 comments

csvan commented

node-forge 0.10.0
Severity: critical
node-forge Package for Node.js lib/debug.js set() Function Prototype Pollution Unspecified Issue - 418sec/forge#1

This issue is fixed in node-forge 1.0.0.
(I doubt anyone has ever used that debug API, including forge itself, so it's probably not "critical".)

csvan commented

Yea I think the classifications are weird sometimes too :-/