Skip to content

react-native-codegen 0.0.7 transitive package unset-value/1.0.0 have known vulnerability security issue #35032

Description

@NarahariTagili-Eaton

Description

react-native-codegen 0.0.7 transitive package unset-value/1.0.0.0 have known vulnerability security issues.
We are using unset-value/1.0.0 transitive package under react-native-codegen 0.0.7 library, unset-value/1.0.0 transitive package having security issue ie.. unset-value is vulnerable to a prototype pollution attack. A remote attacker may be able to execute arbitrary code or cause a denial-of-service (DoS) by tricking the library into modifying or adding properties of Object.prototype. and CVE: BDSA-2021-4507
RCE

We would expect to fix BDSA-2021-4507
RCE) for unset-value/1.0.0 transitive package, upgrading react-native-codegen 0.0.7 latest version

Version

react-native-codegen 0.0.7

Output of npx react-native info

npm WARN deprecated source-map-url@0.4.1: See https://github.com/lydell/source-map-url#deprecated
npm WARN deprecated urix@0.1.0: Please see https://github.com/lydell/urix#deprecated
npm WARN deprecated resolve-url@0.2.1: https://github.com/lydell/resolve-url#deprecated
npm WARN deprecated source-map-resolve@0.5.3: See https://github.com/lydell/source-map-resolve#deprecated
npm WARN deprecated uglify-es@3.3.9: support for ECMAScript is superseded by uglify-js as of v3.13.0

Steps to reproduce

Run the SCA using Blackduck found transitive package unset-value/1.0.0.0 vulnerable and CVE: BDSA-2021-4507
RCE

Snack, code example, screenshot, or link to a repository

NA

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions