QID 983136
QID 983136: Nodejs (npm) Security Update for react-dev-utils (GHSA-29gp-92wp-94q8)
`react-dev-utils` on Windows is vulnerable to remote code execution.
## Recommendation
Update to one of the follow versions, depending on the release line that you are using.
- 1.0.4
- 2.0.2
- 3.1.2
- 4.2.2
- 5.0.2
- 6.0.0-next.a671462c
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-29gp-92wp-94q8 for updates pertaining to this vulnerability.
Vendor References
- GHSA-29gp-92wp-94q8 -
github.com/advisories/GHSA-29gp-92wp-94q8
CVEs related to QID 983136
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-29gp-92wp-94q8 | react-dev-utils |
|