Skip to content

Prototype Pollution vuln due to unset-value sub-dep < 2.0.1 #5725

@olozzalap

Description

@olozzalap

Is there an existing issue for this?

How do you use Sentry?

Sentry Saas (sentry.io)

Which package are you using?

@sentry/nextjs

SDK Version

7.12.1

Framework Version

7.12.1

Link to Sentry event

No response

Steps to Reproduce

  1. Install the latest "@sentry/nextjs": "7.12.1"
  2. Validate with Snyk or similar security vulnerability tool
  3. See affecting Prototype Pollution security vulnerability bug from "unset-value": "<2.0.1" sub-dep. It is part of @sentry/nextjs via: @sentry/[email protected][email protected][email protected][email protected][email protected][email protected][email protected][email protected]

References:

Expected Result

No security vulnerabilities from @sentry/nextjs

Actual Result

See affecting Prototype Pollution security vulnerability bug from "unset-value": "<2.0.1" sub-dep. It is part of @sentry/nextjs via: @sentry/[email protected][email protected][email protected][email protected][email protected][email protected][email protected][email protected]

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions