-
-
Notifications
You must be signed in to change notification settings - Fork 45
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Open vulnerabilities for express-fileupload #55
Comments
Hi, Based on the CVE links you provided CVE-2022-27140 is marked as "disputed". |
yea, is there any plan to upgrade the version express-fileupload to |
Will take a look at that after my vacations. |
Looks like |
thanks @benzino77 for the update and finding 👍 |
I have updated |
Currently, at the latest master e107592, I've observed that express-fileupload using version 1.4.0, which exposes vulnerabilities CVE-2022-27140 (critical) and CVE-2022-27261 (high).
Despite upgrading to version 1.5.0, both vulnerabilities persist in the Express-fileupload library.
Details:
CVE-2022-27140 (CRITICAL): being disputed in the NIST database
CVE-2022-27261 (HIGH): still open, might pose a risk for file overwrite
Previous Discussions:
Issue #312: Link
Issue #316: Link
Do we assess the risks associated with these vulnerabilities, given that we are using express-fileupload: 1.4.0?
The text was updated successfully, but these errors were encountered: