Skip to content

http-proxy vulnerability #2605

Closed
Closed
@panuhorsmalahti

Description

@panuhorsmalahti
  • webpack-dev-server Version: 3.11.0
  • This is a bug
  • This is a modification request

http-proxy, a dependency of webpack-dev-server has a vulnerability.

=== npm audit security report ===                        
                                                                                
                                                                                
                                 Manual Review                                  
             Some vulnerabilities require your attention to resolve             
                                                                                
          Visit https://go.npm.me/audit-guide for additional guidance           
                                                                                
                                                                                
  High            Denial of Service                                             
                                                                                
  Package         http-proxy                                                    
                                                                                
  Patched in      No patch available                                            
                                                                                
  Dependency of   webpack-dev-server [dev]                                      
                                                                                
  Path            webpack-dev-server > http-proxy-middleware > http-proxy       
                                                                                
  More info       https://npmjs.com/advisories/1486       
`-- webpack-dev-server@3.11.0
  `-- http-proxy-middleware@0.19.1
    `-- http-proxy@1.18.0

More info:
http-party/node-http-proxy#1446
https://www.npmjs.com/advisories/1486

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions