Update dependency aws-sdk to v2.814.0 [SECURITY]#123
Open
renovate[bot] wants to merge 1 commit into
Open
Conversation
21524fc to
f6d5a54
Compare
f6d5a54 to
525b6c0
Compare
525b6c0 to
e052a69
Compare
e052a69 to
db4ec31
Compare
db4ec31 to
245a82f
Compare
245a82f to
82e29b7
Compare
82e29b7 to
0f382b2
Compare
7e9ad7e to
49bdd81
Compare
49bdd81 to
2a2ef61
Compare
2a2ef61 to
3aef9e4
Compare
3aef9e4 to
d70f337
Compare
d70f337 to
29cd28b
Compare
29cd28b to
6e6c663
Compare
6e6c663 to
8764f39
Compare
8764f39 to
3ae3719
Compare
3ae3719 to
bd61771
Compare
bd61771 to
bb1d563
Compare
bb1d563 to
63246e1
Compare
63246e1 to
be5eec6
Compare
be5eec6 to
d16ced7
Compare
d16ced7 to
1ed944d
Compare
1ed944d to
68303df
Compare
68303df to
6f772a2
Compare
6f772a2 to
6b646a8
Compare
e06035b to
6eb08a9
Compare
6eb08a9 to
e0c9689
Compare
e0c9689 to
46bc2b4
Compare
46bc2b4 to
32efb79
Compare
32efb79 to
56926a8
Compare
56926a8 to
78b4e85
Compare
78b4e85 to
26ea8f9
Compare
355d8af to
04883f0
Compare
04883f0 to
7805ada
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
2.696.0→2.814.0Prototype Pollution via file load in aws-sdk and @aws-sdk/shared-ini-file-loader
CVE-2020-28472 / GHSA-rrc9-gqf8-8rwg
More information
Details
This affects the package @aws-sdk/shared-ini-file-loader before 1.0.0-rc.9; the package aws-sdk before 2.814.0. If an attacker submits a malicious INI file to an application that parses it with loadSharedConfigFiles , they will pollute the prototype on the application. This can be exploited further depending on the context.
Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:LReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Release Notes
aws/aws-sdk-js (aws-sdk)
v2.814.0Compare Source
v2.813.0Compare Source
v2.812.0Compare Source
v2.811.0Compare Source
v2.810.0Compare Source
v2.809.0Compare Source
v2.808.0Compare Source
v2.807.0Compare Source
v2.806.0Compare Source
v2.805.0Compare Source
v2.804.0Compare Source
v2.803.0Compare Source
v2.802.0Compare Source
Profilethat was included in release, v2.801.0v2.801.0Compare Source
v2.800.0Compare Source
v2.799.0Compare Source
v2.798.0Compare Source
v2.797.0Compare Source
v2.796.0Compare Source
v2.795.0Compare Source
v2.794.0Compare Source
v2.793.0Compare Source
v2.792.0Compare Source
v2.791.0Compare Source
v2.790.0Compare Source
v2.789.0Compare Source
v2.788.0Compare Source
v2.787.0Compare Source
v2.786.0Compare Source
v2.785.0Compare Source
v2.784.0Compare Source
v2.783.0Compare Source
v2.782.0Compare Source
v2.781.0Compare Source
v2.780.0Compare Source
v2.779.0Compare Source
v2.778.0Compare Source
v2.777.0Compare Source
v2.776.0Compare Source
v2.775.0Compare Source
v2.774.0Compare Source
v2.773.0Compare Source
v2.772.0Compare Source
v2.771.0Compare Source
v2.770.0Compare Source
v2.769.0Compare Source
v2.768.0Compare Source
v2.767.0Compare Source
v2.766.0Compare Source
v2.765.0Compare Source
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.