Skip to content

Cybersource SDK using vulnerable package versions as transitive dependencies #192

@KKonstantinov

Description

@KKonstantinov

Hello,

Is it possible to get package bumps that resolve CVEs?

✗ Uncaught Exception [High Severity][https://security.snyk.io/vuln/SNYK-JS-UNDICI-15518070] in undici@5.29.0
introduced by cybersource-rest-client@0.0.76 > axios-cookiejar-support@4.0.7 > http-cookie-agent@5.0.4 > undici@5.29.0 and 1 other path(s)
This issue was fixed in versions: 6.24.0, 7.24.0

Thanks

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions