简体   繁体   English

在 jsonwebtoken-8.5.1.tgz - ibmcloud-appid 中检测到 CVE-2022-23529(高)

[英]CVE-2022-23529 (High) detected in jsonwebtoken-8.5.1.tgz - ibmcloud-appid

We are getting there is one high vulnerability related to jsonwebtoken and which is dependent package of ibmcloud-appid.我们得到了一个与 jsonwebtoken 相关的高漏洞,它依赖于 ibmcloud-appid 的 package。 ibmcloud-appid I have already upgraded to latest but still in package-lock.json jsonwebtoken version is 8.5.1. ibmcloud-appid 我已经升级到最新但仍然在 package-lock.json jsonwebtoken 版本是 8.5.1。 Here in vulnerability jsonwebtoken is recommend to upgrade version to 9.0.0.这里漏洞jsonwebtoken建议升级到9.0.0版本。 So how i can upgrade package-lock.json dependent package, as that is not present in package.json?那么我如何升级 package-lock.json 依赖 package,因为它不存在于 package.json 中?

A new version of ibmcloud-appid with the fixed vulnerability will be released soon.修复漏洞的新版ibmcloud-appid即将发布。 Please keep an eye on the following issue for updates请关注以下问题更新

https://github.com/ibm-cloud-security/appid-serversdk-nodejs/issues/286 https://github.com/ibm-cloud-security/appid-serversdk-nodejs/issues/286

声明:本站的技术帖子网页,遵循CC BY-SA 4.0协议,如果您需要转载,请注明本站网址或者原文地址。任何问题请咨询:yoyou2525@163.com.

 
粤ICP备18138465号  © 2020-2024 STACKOOM.COM