Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security Issue [Denial of Service] #268

Open
axago opened this issue Nov 7, 2019 · 5 comments
Open

Security Issue [Denial of Service] #268

axago opened this issue Nov 7, 2019 · 5 comments

Comments

@axago
Copy link

axago commented Nov 7, 2019

Remediation : Upgrade to version 4.4.5 or later.

Screen Shot 2019-11-07 at 22 38 18

@UziTech
Copy link

UziTech commented Nov 7, 2019

PR #267 should fix this

@audiBookning
Copy link

Is this project abandoned?
I ask this because the above simple PR has no answers for so much time.
I do appreciate the work done here, but i feel that i have to look somewhere else for a solution.

Nonetheless thanks for all the effort put in here that have no doubt benefited so many people.

@BillGR17
Copy link

BillGR17 commented Jan 6, 2020

I am running npm v6.13.4
I dont see any security issues with express-hadlebars
handlebars appears to be updating to latest by default
hbs

@audiBookning
Copy link

True. It would pass since package.json has in the dependencies: "handlebars": "^4.1.2".

I was talking about the lack of feedback on this and others issues, since some month ago.
I was asking: Is the package totally "in the wild"?

I was making a side comment, not wanting to create a whole new issue for that and also not seeking to overextend and sidetrack too much the goal of this one. Sorry it seem it was badly executed, since it was just a ping to the package devs or maintainers.

@BillGR17
Copy link

BillGR17 commented Jan 6, 2020

I get what you are saying now.
I don't know the answer to that question sorry.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants