QID 980247
QID 980247: Nodejs (npm) Security Update for uglify-js (GHSA-34r7-q49f-h37c)
Versions of `uglify-js` prior to 2.4.24 are affected by a vulnerability which may cause crafted JavaScript to have altered functionality after minification.
## Recommendation
Upgrade UglifyJS to version >= 2.4.24.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-34r7-q49f-h37c for updates pertaining to this vulnerability.
Vendor References
- GHSA-34r7-q49f-h37c -
github.com/advisories/GHSA-34r7-q49f-h37c
CVEs related to QID 980247
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-34r7-q49f-h37c | uglify-js |
|