Skip to content

cve-2023-45853: zlib version in node dependency showing up in scans #195

Open
@reidsm

Description

@reidsm

Hello,

node version 18.20.5, running on linux

In our recent scans we have detected the following CVE:
https://nvd.nist.gov/vuln/detail/cve-2023-45853

The description was updated on Dec 20 to include zlib versions <= 13.1 which appears to be why our scans are suddenly flagging the issue. The version in node 18.20.5 (going up to at least node v22) appears to be 1.3.0.1. Is there a plan to patch this version in the near future?

Thank you.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions