Skip to content

CVE-2022-24434 (issue #882) #1011

Closed
Closed
@anka-213

Description

@anka-213

Issue #882 shouldn't have been closed, since it wasn't actually fixed by upgrading multer to 1.4.4. As we can see on https://security.snyk.io/vuln/SNYK-JS-DICER-2311764, there is currently no version of dicer that fixes the issue, so a version bump was not sufficient.

Edit: it seems like the latest version of multer: 1.4.5-lts.1 does fix the issue. However it supports slightly fewer node versions than multer-1.4.4

Metadata

Metadata

Assignees

No one assigned

    Labels

    status: needs triageIssues which needs to be reproduced to be verified report.type: fixIssues describing a broken feature.

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions