-
Notifications
You must be signed in to change notification settings - Fork 425
Closed
Labels
dependenciesPull requests that update a dependency filePull requests that update a dependency filesecuritysemver:patch
Milestone
Description
Hi, the latest @slack/bolt@3.19.0 is using axios@1.7.2 that allows Server-Side Request Forgery via unexpected behavior where requests for path relative URLs get processed as protocol relative URLs. This high vulnerability is failing in our CI pipeline and blocking releases.
Requirements
Axios version should be upgraded to 1.7.3 to address CVE-2024-39338
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
dependenciesPull requests that update a dependency filePull requests that update a dependency filesecuritysemver:patch