Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Prototype Pollution #8501

Closed
CoMaDaniel opened this issue Feb 23, 2021 · 2 comments
Closed

Prototype Pollution #8501

CoMaDaniel opened this issue Feb 23, 2021 · 2 comments

Comments

@CoMaDaniel
Copy link

Hello all.
I was looking into using chart.js, but due to some company policy, we need to research the stability and security of new third party code we introduce.
There seems to be a high vulnerability issue regarding Prototype Pollution (https://snyk.io/vuln/SNYK-JS-CHARTJS-1018716) in the current version.
Is this the case? Is it looking to be fixed in the newer version? When will 3.0 be available?
Thank you! Keep up the hard work!

@LeeLenaleee
Copy link
Collaborator

Seems to be fixed in #7920, snyk also says its vulnerable in versions prior to 2.9.4 (latest stable)

@CoMaDaniel
Copy link
Author

Great! Thanks for the fast reply!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants