-
Type: Bug
-
Status: Resolved
-
Priority: Major
-
Resolution: Fixed
-
Affects Version/s: None
-
Component/s: Web UI
-
Release Notes Summary:Upgrade webpack-dev-server and webpack-cli version
-
Tags:
-
Sprint:UI COOLDOWN - 2024-8, UI - 2024-9
-
Story Points:3
SRCCLR-SID-37811 | Unknown
Severity : High
unset-value is vulnerable to prototype pollution. An attacker can inject properties into existing construct prototypes via the `module.exports` function in `index.js` and modify attributes such as `_proto_`, `constructor`, and `prototype` base objects.
Module : unset-value
nuxeo-web-ui.zip#zip:packages/nuxeo-designer-catalog/node_modules:unset-value
Current Version : 1.0.0
Recommended Upgrade Version : 2.0.1