MGASA-2023-0035

Source
https://advisories.mageia.org/MGASA-2023-0035.html
Import Source
https://advisories.mageia.org/MGASA-2023-0035.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2023-0035
Related
Published
2023-02-07T00:06:39Z
Modified
2023-02-06T22:58:13Z
Summary
Updated nodejs-minimist packages fix security vulnerability
Details

Minimist <=1.2.5 is vulnerable to Prototype Pollution via file index.js, function setKey() (lines 69-95). (CVE-2021-44906)

References
Credits

Affected packages

Mageia:8 / nodejs-minimist

Package

Name
nodejs-minimist
Purl
pkg:rpm/mageia/nodejs-minimist?distro=mageia-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.2.7-1.mga8

Ecosystem specific

{
    "section": "core"
}