Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

react-scripts - CVE-2024-33883 for ejs module shipped with react-scripts - CVSS 9.8 #13590

Open
sertechside opened this issue May 16, 2024 · 1 comment

Comments

@sertechside
Copy link

sertechside commented May 16, 2024

Describe the bug

CVE-2024-33883 - react-scripts ejs module - CVSS 9.8 - GHSA-ghr5-ch3p-vcr6
The ejs module. is embedded in react-script along with other modules.

react-scripts-5.1.0-next.14.tgz ->workbox-webpack-plugin-6.6.60.tgz-workbox-build-6.6.0.tgs -> rollup-plugin-off-main-thread-2.2.3.tgx->ejs3.1.9

(Write your answer here.)
would you please check and make sure to provide fixed react-scripts w updated/fixed modules (eg.ejs3.1.10).
thank you. kind regards,

Did you try recovering your dependencies?

(Write your answer here.)

Which terms did you search for in User Guide?

(Write your answer here if relevant.)

Environment

(paste the output of the command here.)

Steps to reproduce

(Write your steps here:)

Expected behavior

(Write what you thought would happen.)

Actual behavior

(Write what happened. Please add screenshots!)

Reproducible demo

(Paste the link to an example project and exact instructions to reproduce the issue.)

@sertechside
Copy link
Author

hi @saimonmoore , is react-scripts still supported? could you please assign it a maintaner for update? thank you. kind regards.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant