NodeJS/requirejs/1.0.7
Node adapter for RequireJS, for loading AMD modules. Includes RequireJS optimizer
https://www.npmjs.com/package/requirejs
BSD OR MIT
1 Security Vulnerabilities
jrburke requirejs vulnerable to prototype pollution
Published date: 2024-07-01T15:32:19Z
CVE: CVE-2024-38999
Links:
- https://nvd.nist.gov/vuln/detail/CVE-2024-38999
- https://gist.github.com/mestrtee/9acae342285bd2998fa09ebcb1e6d30a
- https://github.com/advisories/GHSA-x3m3-4wpv-5vgc
- https://github.com/requirejs/r.js/issues/1015
- https://github.com/requirejs/requirejs/issues/1854
- https://github.com/requirejs/requirejs/pull/1856/commits/ebd7a2ff71473542fa132d0d15c10fb4ed1539e1
- https://security.snyk.io/vuln/SNYK-JS-REQUIREJS-5416713
jrburke requirejs v2.3.6 was discovered to contain a prototype pollution via the function s.contexts._.configure. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
Affected versions: ["2.3.6", "2.3.5", "2.3.4", "2.3.3", "2.3.2", "2.3.1", "2.3.0", "2.2.0", "2.1.22", "2.1.21", "2.1.20", "2.1.19", "2.1.18", "2.1.17", "2.1.16", "2.1.15", "2.1.14", "2.1.13", "2.1.12", "2.1.11", "2.1.10", "2.1.9", "2.1.8", "2.1.7", "2.1.6", "2.1.5", "2.1.4", "2.1.3", "2.1.2", "2.1.1", "2.1.0", "2.0.6", "2.0.5", "2.0.4", "2.0.3", "2.0.2", "2.0.1", "2.0.0", "1.0.8", "1.0.7", "1.0.6", "1.0.5", "1.0.4", "1.0.3", "1.0.2", "1.0.1", "1.0.0", "0.27.1", "0.27.0", "0.26.0"]
Secure versions: [2.3.7, 2.3.8]
Recommendation: Update to version 2.3.8.
52 Other Versions
| Version | License | Security | Released | |
|---|---|---|---|---|
| 0.27.0 | BSD OR MIT | 1 | 2011-10-03 - 06:00 | over 14 years |
| 0.26.0 | BSD OR MIT | 1 | 2011-08-17 - 06:45 | over 14 years |
