SNOW-1621414: Update fast-xml-parser package to v4.4.1 to Fix ReDOS Vulnerability #885
Labels
invalid
This doesn't seem right
status-triage_done
Initial triage done, will be further handled by the driver team
What is the current behavior?
Currently Snowflake-SDK using the "fast-xml-parser" version of "^4.2.5", But version below 4.4.1 is having ReDOS vulnerability. GHSA-mpg4-rc92-vx8v
What is the desired behavior?
To fix ReDOS vulnerability, need to update "fast-xml-parser" to "^4.4.1"
How would this improve
snowflake-connector-nodejs
?It fixes ReDOS vulnerability
References, Other Background
Please go through link for more info,
Vulnerability : GHSA-mpg4-rc92-vx8v
The text was updated successfully, but these errors were encountered: