SAP Knowledge Base Article - Preview

3688976 - js-yaml has prototype pollution in merge

Symptom

  • npm audit reports the following vulnerability:

js-yaml 4.0.0 - 4.1.0Severity: moderate

js-yaml has prototype pollution in merge (<<)https://github.com/advisories/GHSA-mh29-5h37-fv8mnode_modules/@sap/cds-dk/node_modules/js-yaml 

  • npm list js-yaml , shows +-- @sap/cds-dk@9.4.3 


Read more...

Environment

SAP CAP – tools, IDEs, build, deployment

Product

CP PC APM SERVICE all versions

Keywords

npm audit, js-yaml vulnerability, prototype pollution, @sap/cds-dk, moderate severity, Node.js, npm audit fix, design-time package, SAP CAP , KBA , BC-XS-CDX-TLS , SAP CAP – tools, IDEs, build, deployment , Problem

About this page

This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).

Search for additional results

Visit SAP Support Portal's SAP Notes and KBA Search.