Skip to content

Missing Handler in @scandipwa/magento-scripts

Critical
ejnshtein published GHSA-52qp-gwwh-qrg4 Jun 14, 2021

Package

npm @scandipwa/magento-scripts (npm)

Affected versions

1.5.1 || 1.5.2

Patched versions

1.5.3

Description

Impact

After changing the function from synchronous to asynchronous there wasn't implemented handler in the start, stop, exec and logs commands, effectively making them unusable.

Patches

Version 1.5.3 contains patches for the problems described above.

Workarounds

Upgrade to patched or latest (recommended) version npm i @scandipwa/[email protected] or npm i @scandipwa/magento-scripts@latest.

References

New releases always available here: https://github.com/scandipwa/create-magento-app/releases

For more information

If you have any questions or comments about this advisory:

Severity

Critical

CVE ID

CVE-2021-32684

Weaknesses