[ 
https://issues.apache.org/jira/browse/THRIFT-5427?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18112797#comment-18112797
 ] 

Sylwester Lachiewicz edited comment on THRIFT-5427 at 9/8/26 1:45 PM:
----------------------------------------------------------------------

The root package.json depends on {{ws}} at {{^8.21.0}}, past the 7.4.6 this 
ticket asked for; the vulnerable 5.2.2 pin from 0.14.1 is gone. Resolving as 
Fixed.


was (Author: slachiewicz):
lib/nodejs carries no runtime {{ws}} dependency (the only reference is in a 
test package-lock). The vulnerable dependency this ticket describes is gone 
from the library. Resolving as Fixed.

> Thrift v0.14.1 contains dependecy to vulnerable `ws` module
> -----------------------------------------------------------
>
>                 Key: THRIFT-5427
>                 URL: https://issues.apache.org/jira/browse/THRIFT-5427
>             Project: Thrift
>          Issue Type: Bug
>          Components: Node.js - Library
>    Affects Versions: 0.14.1
>            Reporter: Hitendra Singh Hada
>            Priority: Major
>
> Currently thrift v0.14.1 contains dependecy of `ws` module v5.2.2 which is 
> vulnerable. To fix the vulnerability you need to update `ws` module with 
> version 7.4.6. Please have a look and advise ETA.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to