From 1e18423234495b1e382d33147ee9cde6d1bc7b0d Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Vladim=C3=ADr=20Gorej?= Date: Tue, 8 Oct 2024 12:14:29 +0200 Subject: [PATCH] fix(security): fix unsafe cookie serialization (#3680) Fix was provided by updating cookie to v0.7.2. Refs CVE-2024-47764 Refs GHSA-pxg6-pf52-xh8x --- package-lock.json | 2 +- package.json | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/package-lock.json b/package-lock.json index 71720472e..88c225fdf 100644 --- a/package-lock.json +++ b/package-lock.json @@ -15,7 +15,7 @@ "@swagger-api/apidom-json-pointer": ">=1.0.0-alpha.9 <1.0.0-beta.0", "@swagger-api/apidom-ns-openapi-3-1": ">=1.0.0-alpha.9 <1.0.0-beta.0", "@swagger-api/apidom-reference": ">=1.0.0-alpha.9 <1.0.0-beta.0", - "cookie": "~0.7.0", + "cookie": "~0.7.2", "deepmerge": "~4.3.0", "fast-json-patch": "^3.0.0-1", "js-yaml": "^4.1.0", diff --git a/package.json b/package.json index 4fd0df166..ee2d46e5a 100644 --- a/package.json +++ b/package.json @@ -78,7 +78,7 @@ "@swagger-api/apidom-json-pointer": ">=1.0.0-alpha.9 <1.0.0-beta.0", "@swagger-api/apidom-ns-openapi-3-1": ">=1.0.0-alpha.9 <1.0.0-beta.0", "@swagger-api/apidom-reference": ">=1.0.0-alpha.9 <1.0.0-beta.0", - "cookie": "~0.7.0", + "cookie": "~0.7.2", "deepmerge": "~4.3.0", "fast-json-patch": "^3.0.0-1", "js-yaml": "^4.1.0",