You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
I don't know that these CVE's actually impact the way nbclassic is used in practice, but they cause marked (and so nbclassic) to get flagged as insecure by some vulnerability scanning tools, so it would be great to upgrade marked to 4.0.10 when possible.
The text was updated successfully, but these errors were encountered:
The bundled javascript dependency
marked
is currently pinned to~1.1.1
here. This version has several CVE's opened against it:CVE-2022-21680 (affects marked <4.0.10):
https://www.mend.io/vulnerability-database/CVE-2022-21680
CVE-2021-21306 (affects marked <2.0.0):
https://www.mend.io/vulnerability-database/CVE-2021-21306
CVE-2022-21681 (affects marked <4.0.10):
https://www.mend.io/vulnerability-database/CVE-2022-21681
I don't know that these CVE's actually impact the way nbclassic is used in practice, but they cause
marked
(and so nbclassic) to get flagged as insecure by some vulnerability scanning tools, so it would be great to upgrademarked
to 4.0.10 when possible.The text was updated successfully, but these errors were encountered: