npm / ini

An ini parser/serializer in JavaScript

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

[BUG] Prototype Pollution [High Severity]

mattpilleul opened this issue · comments

What / Why

High Severity security issue with ini@1.3.5

When

  • Whenever I launch a Snyk Dependencies Audit.

Current Behavior

  • Can't user bcrypt@5.0.0 with this current security issue.

Images

https://postimg.cc/vxRg3cHg | Snyk Audit
https://postimg.cc/Zvr9g4Cf | Yarn.lock

This was fixed in v1.3.6 (56d2805).