QID 983574
QID 983574: Nodejs (npm) Security Update for zrender (GHSA-fhv8-fx5f-7fxf)
Security update has been released for zrender to fix the vulnerability. Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
Using `merge` and `clone` helper methods in the `src/core/util.ts` module will have prototype pollution. It will affect the popular data visualization library Apache ECharts, which is using and exported these two methods directly.
Solution
It has been patched in https://github.com/ecomfe/zrender/pull/826.
Users should update zrender to `5.2.1`. and update echarts to `5.2.1` if project is using echarts.
Vendor References
- GHSA-fhv8-fx5f-7fxf -
github.com/advisories/GHSA-fhv8-fx5f-7fxf
CVEs related to QID 983574
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-fhv8-fx5f-7fxf | zrender |
|