Project

General

Profile

Actions

Task #103722

closed

Detected vulnerability with package 'enshrined/svg-sanitize'

Added by Lars Tode 7 months ago. Updated 5 months ago.

Status:
Closed
Priority:
Should have
Assignee:
-
Category:
Miscellaneous
Target version:
-
Start date:
2024-04-25
Due date:
% Done:

100%

Estimated time:
TYPO3 Version:
12
PHP Version:
8.0
Tags:
Complexity:
Sprint Focus:

Description

The currently use of package enshrined/svg-sanitize with version constrain ^0.15.4 increase the risk score of TYPO3 projects.

The corresponding CVEs are

Even the two mentioned CVEs are false-positive CVEs and should not bothered the project, these have an effect of the risk score.

The package should be updated to a newer version in order to solve this issue.

As of today, the current version available of this package is 0.18.0


Files

DependencyTrack.png (33.3 KB) DependencyTrack.png Lars Tode, 2024-04-25 09:35
103722-1.png (286 KB) 103722-1.png Oliver Hader, 2024-04-25 10:06
103722-2.png (223 KB) 103722-2.png Oliver Hader, 2024-04-25 10:06

Related issues 3 (0 open3 closed)

Related to TYPO3 Core - Bug #100234: Incorporate tests of enshrined/svg-sanitize:v0.16.0RejectedOliver Hader2023-03-21

Actions
Related to TYPO3 Core - Task #100233: Upgrade enshrined/svg-sanitize to ^0.16Rejected2023-03-20

Actions
Related to TYPO3 Core - Bug #104611: Raise enshrined/svg-sanitize:^0.19.0Closed2024-08-13

Actions
Actions

Also available in: Atom PDF