You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The ip package before 1.1.9 for Node.js might allow SSRF because some IP addresses (such as 0x7f.1) are improperly categorized as globally routable via isPublic. https://nvd.nist.gov/vuln/detail/CVE-2023-42282
We should probably release a new version of vroom-docker for these CVE fixes? I think you only release when there's a new version of vroom though right?
This has already been fixed in later versions of
node:20-bookworm-slim
. So fix is to build a new docker imageThe text was updated successfully, but these errors were encountered: