dougb1968

Is there any response to address the vulnerability reported in CVE-2020-28458?

"All versions of package are vulnerable to Prototype Pollution due to an incomplete fix for"


  allan

    I believe the fix for that issue was in this commit, which was included in DataTables 1.10.23 (18th Dec 2020) and every release since then.

    It looks like that CVE entry has just not been updated to take account of that. I've sent Snyk an e-mail asking them if they could update the CVE to reflect that it has been fixed for over two years now.


  dougb1968

    Perfect. Thank you!

