Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2023-28155 security vulnerability #2986

Open
himanshu-bhoraniya-exa opened this issue Sep 29, 2023 · 0 comments
Open

CVE-2023-28155 security vulnerability #2986

himanshu-bhoraniya-exa opened this issue Sep 29, 2023 · 0 comments

Comments

@himanshu-bhoraniya-exa
Copy link

There's vulnerability introduces is related to the https://www.npmjs.com/package/request is
https://www.cvedetails.com/cve/CVE-2023-28155/

request is not directly connected to @looker/filter-components but through @looker/filter-components -> @looker/sdk -> request

Here @looker/sdk uses request v^2.88.0 which when installed get to version 2.88.2.

As per vulnerability check - CVE-2023-28155 is introduced through v2.88.1 and greater.

A possible solution to vulnerability is to lower the version related to the request from ^2.88.0 to fixed 2.88.0 or depending on another package instead of request.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant