Skip to content

Potential exposure to CVE-2021-3918 - Score 9.8 #158

@felix-hcl

Description

@felix-hcl

Steps to reproduce

  1. Install loopback-connector-rest
  2. run npm ls json-schema

Current Behavior

The vulnerable version of json-schema is a sub-dependency of [email protected] which is the latest version of the deprecated http client.

Expected Behavior

Usage of non-deprectated package which are not exposed to security vulnerabilities.

Additional information

https://nvd.nist.gov/vuln/detail/CVE-2021-3918
Fixes exist for json-schema, jsprim and http-signature but request does not accept [email protected] which would resolve this issue:
https://github.com/joyent/node-http-signature/blob/master/CHANGES.md#136

Related Issues

#147

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions