Skip to content

Suppress low severity as bumping to latest express session doesn't resolves the issue#1804

Open
nitinprabhuhmcts wants to merge 1 commit intomasterfrom
suppress-on-headers-cve-2025-7339
Open

Suppress low severity as bumping to latest express session doesn't resolves the issue#1804
nitinprabhuhmcts wants to merge 1 commit intomasterfrom
suppress-on-headers-cve-2025-7339

Conversation

@nitinprabhuhmcts
Copy link
Contributor

Security Vulnerability Assessment

  • CVE-2025-7339 is suppressed as updating express session doesn't include on headers version 1.10.0 or higher.
  • As this is low severity suppressing it until we have fix is available in expression session module(with on headers version >=1.10.0)

CVE Suppression: Are there any CVEs present in the codebase (either newly introduced or pre-existing) that are being intentionally suppressed or ignored by this commit?

  • Yes
  • No

@nitinprabhuhmcts nitinprabhuhmcts requested a review from a team as a code owner July 21, 2025 16:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant