Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

misc: braces: fails to limit the number of characeters it can handle #8626

Open
dongpingx opened this issue Jun 17, 2024 · 0 comments
Open
Labels
status: new The issue status: new for creation

Comments

@dongpingx
Copy link
Contributor

Trivy Vulnerability Scan Results (misc/config_tools/configurator/yarn.lock)

VulnerabilityID Severity CVSS Score Title Library Vulnerable Version Fixed Version Information URL
CVE-2024-4068 HIGH   braces: fails to limit the number of characters it can handle braces 3.0.2 3.0.3 https://avd.aquasec.com/nvd/cve-2024-4068
@dongpingx dongpingx added the status: new The issue status: new for creation label Jun 17, 2024
dongpingx added a commit to dongpingx/acrn-hypervisor that referenced this issue Jun 17, 2024
Although my former patch can pass through build procedure but when
I launch configurator and try to load board.xml, the loading
procedure wont finish. So we cannot step forward anymore.

I cannot find a solution right now, so I have to fix the version
to v3.2.33 for several weeks.

This patch is applied to fix vulnerability scanned by Trivy also.
Vulnerability ID is CVE-2024-4068 & fixed version of dependency is 3.0.3.
I added one configuration item named override for package.json.

I tested and confirmed the fix is ok.

Signed-off-by: dongpingx <[email protected]>
Tracked-On: projectacrn#8626
acrnsi-robot pushed a commit that referenced this issue Jun 18, 2024
Although my former patch can pass through build procedure but when
I launch configurator and try to load board.xml, the loading
procedure wont finish. So we cannot step forward anymore.

I cannot find a solution right now, so I have to fix the version
to v3.2.33 for several weeks.

This patch is applied to fix vulnerability scanned by Trivy also.
Vulnerability ID is CVE-2024-4068 & fixed version of dependency is 3.0.3.
I added one configuration item named override for package.json.

I tested and confirmed the fix is ok.

Signed-off-by: dongpingx <[email protected]>
Tracked-On: #8626
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
status: new The issue status: new for creation
Projects
None yet
Development

No branches or pull requests

1 participant