Skip to content

Vulnerable class-validator with CVE-2019-18413 being pulled in, mitigations may need to be applied ! #880

@yahanvesh

Description

@yahanvesh

Summary

Based on the discussion typestack/class-validator#438, currently there is no fixed version of class-validator which fixes the CVE-2019-18413.
However a mitigation is suggested at typestack/class-validator#438 (comment) about the use of a previously undocumented option.

Expected Behavior

Respective changes as needed to be made to use the mitigations suggested at typestack/class-validator#438 (comment)

Current Behavior

Currently the latest version of javascript-obfuscator pulls in class-validator which has a vulnerable CVE.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions