Bug#991524: unblock: node-jszip/3.5.0+dfsg-2

2021-07-26 Thread Yadd
Le 26/07/2021 à 22:01, Yadd a écrit : > Package: release.debian.org > Severity: normal > User: release.debian@packages.debian.org > Usertags: unblock > > Please unblock package node-jszip > > [ Reason ] > node-jszip is vulnerable to a prototype pollution: rafting a new zip file > with

Bug#991524: unblock: node-jszip/3.5.0+dfsg-2

2021-07-26 Thread Yadd
Package: release.debian.org Severity: normal User: release.debian@packages.debian.org Usertags: unblock Please unblock package node-jszip [ Reason ] node-jszip is vulnerable to a prototype pollution: rafting a new zip file with filenames set to Object prototype values (e.g __proto__,