Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Vulnerability Found: Missing Release of Resource after Effective Lifetime (SNYK-JS-INFLIGHT-6095116) #1053

Open
lacort opened this issue Oct 10, 2024 · 1 comment

Comments

@lacort
Copy link

lacort commented Oct 10, 2024

Hello !!

It has been identified that [email protected] introduces a missing release of resource after effective lifetime vulnerability via a transitive dependency. The vulnerability is linked to the package [email protected], as reported in the Snyk vulnerability database: SNYK-JS-INFLIGHT-6095116.

Vulnerability Path:

Severity: Medium Severity

Recommended Actions:

Currently, no patch or upgrade is available to address this vulnerability. I recommend that the team investigate possible mitigations, whether by updating or removing the affected transitive dependencies, or by finding alternative solutions to reduce the security risk.

Thank you for your attention to this issue.

@madugba
Copy link

madugba commented Oct 10, 2024

This has been a major challenge for me, I try writing an alternative patch for it seems not to still work. I know this is not yet been exploited but I think an urgent update is needed.
inflight Missing Release of Resource after Effective Lifetime
And to the best of my knowledge, inflight is out dated and is not being maintained.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants