Skip to content

Security concern: CWE-400 via d3-color #378

@kikienelsone

Description

@kikienelsone

Hi!

We`re currently using 'react-simple-map' in our project, and noticed that it indirectly depends on 'd3-color'.
This version of 'd3-color' is affected by a vulnerability classified as CWE-400: Uncontrolled Resource Consumption. The issue has been reported in our audit tools

The issue is fixed in d3-color@3.1.0, but react-simple-maps depends on packages (like d3-interpolate) that still pull in the vulnerable version.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions