CVE-2024-21538 in latest Node v18 #200
Labels
dont-believe-affects-nodejs
dont-fall-in-threat-model
When a vulnerability might affect Node.js but do not fall in the Node.js threat model
v18.x
Version
v18.20.6
Platform
Subsystem
npm
What steps will reproduce the bug?
How often does it reproduce? Is there a required condition?
Always reproducible
What is the expected behavior? Why is that the expected behavior?
No CVE found
What do you see instead?
Additional information
Upgrading npm package to 10.9.1 will fix the vulnerability, see npm/cli@029060c
Was done for main and v20 with nodejs/node#56135
The text was updated successfully, but these errors were encountered: