The new dependency PHPSecLib has a published CVE

Created on 12 March 2023, almost 2 years ago
Updated 16 March 2023, almost 2 years ago

Problem/Motivation

The latest dev release introduces a dependency for "phpseclib/phpseclib": "3.0.18",. However, there is CVE-2023-27560 for PHPSecLib versions below 3.0.19

Proposed resolution

Please update the constraint to use at least 3.0.19 and allow for higher versions too.

🐛 Bug report
Status

Fixed

Version

1.0

Component

Code

Created by

🇩🇪Germany jurgenhaas Gottmadingen

Live updates comments and jobs are added and updated live.
Sign in to follow issues

Comments & Activities

Production build 0.71.5 2024