Skip to content

Security Warning: CVE-2021-44228 flagged by Wiz #483

@SomethingNew71

Description

@SomethingNew71

Hey!

I'm opening this issue because my security scanner (Wiz) flagged a potential vulnerability: GHSA-jfh8-c2jp-5v3q (Log4Shell) in a project that uses react-native-get-random-values.

This is breaking a number of our builds within the corporate finance sector. Is there any chance you can use a different library to accomplish this goal or remove this library?

Here's the context:

Package: react-native-get-random-values
Link to your package.json - https://github.com/coveo/coveo.analytics.js/blob/master/package.json#L28
Dependency tree: indirectly used through coveo.analytics

Scanner: Wiz

CVE: CVE-2021-44228

Additionally, I have opened a PR in the offending app, but I am not sure it's actually maintained anymore

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions