Details
-
Bug
-
Status: Closed
-
Major
-
Resolution: Won't Fix
-
None
-
None
Description
There are known security vulnerabilities in dependencies of current version of express: qs@0.4.x and connect@1.x. See https://nodesecurity.io/advisories/qs_dos_extended_event_loop_blocking and https://nodesecurity.io/advisories/methodOverride_Middleware_Reflected_Cross-Site_Scripting for more detail. Can we bump express so that these vulnerabilities go away?