Security: sanitize-html 2.12.1 and apostrophe 3.63.1 #4436
boutell
announced in
Release Notes
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
In this release of
apostrophe, we bumped our dependency onsanitize-htmlto^2.12.1at a minimum, to ensure thatnpm update apostropheis sufficient to guarantee a security update is installed.Version 2.12.1 of
sanitize-htmlis a security update, which prevents specially crafted HTML documents from revealing the existence or non-existence of files on the server. The vulnerability did not expose any other information about those files.Thanks to the Snyk Security team for the disclosure and to Dylan Armstrong for the fix.
Beta Was this translation helpful? Give feedback.
All reactions