coldbox-elixir@3.0.0-alpha.13 vulnerabilities

A wrapper around Webpack specifically for ColdBox applications

  • latest version

    4.0.5

  • latest non vulnerable version

  • first published

    8 years ago

  • latest version published

    1 years ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the coldbox-elixir package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • L
    Information Exposure

    coldbox-elixir is an A wrapper around Webpack specifically for ColdBox applications

    Affected versions of this package are vulnerable to Information Exposure via the DefinePlugin function in src/defaultConfig.js. Attackers can reveal the contents of environment variables.

    How to fix Information Exposure?

    Upgrade coldbox-elixir to version 3.1.7 or higher.

    <3.1.7