-
Notifications
You must be signed in to change notification settings - Fork 576
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
【安全漏洞】NPM IP package vulnerable to Server-Side Request Forgery (SSRF) attacks #1294
Comments
see pr: #1292 |
Hi , |
This vulnerability still exists... how would this be handled ? |
@borisLipmanovich PR #1292 closed, but not merged. holy shit! urllib version is still 2.41.0 |
@xiaweiss, indeed :) Can anyone handle it? |
@borisLipmanovich |
@borisLipmanovich please @ repo owner,not me. |
I'm just giving feedback, I don't have any access |
Version 6.21.0 has been released |
The bundle size is just getting bigger an bigger, please remember this is also a browser package, and 700kb plus even not gzipped is huge... this package should be shaken, to only import what you need. |
ali-oss@6.20.0 => urllib@2.41.0 => ip@1.1.5
The text was updated successfully, but these errors were encountered: