-
Notifications
You must be signed in to change notification settings - Fork 336
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[GHSA-cm5g-3pgc-8rg4] A vulnerability has been identified in the Express... #5024
[GHSA-cm5g-3pgc-8rg4] A vulnerability has been identified in the Express... #5024
Conversation
Thanks for the PR @axi92. You don't happen to know if this has been fixed or not do you? |
I don't know how to validate it myself and there are mixed informations.
But according to snyk it should be fixed in 4.x https://security.snyk.io/vuln/SNYK-JS-EXPRESS-8310337 I opened an issue asking in the express repo, they should know for sure. |
Hmmmm. That issue seems to have been deleted |
I tried to find an email to notify them but I was not able to find one in the express repo. |
According to https://github.com/expressjs/express/blob/master/Security.md it seems they suggest emailing a lead dev.
You're the author of https://www.herodevs.com/vulnerability-directory/cve-2024-10491 correct? Can you rerun your poc on newer versions? |
Yes but I was not able to find the mail of the lead dev. No I am not the author, and I tried the poc on different versions with everytime the same result. |
I see. Well failing more independent review I guess I'll merge this as is. Thanks for the PR 👍 |
966c2ac
into
axi92/advisory-improvement-5024
Hi @axi92! Thank you so much for contributing to the GitHub Advisory Database. This database is free, open, and accessible to all, and it's people like you who make it great. Thanks for choosing to help others. We hope you send in more contributions in the future! |
Updates
Comments
Add info from herodevs.com about version and package