patches v1.4.2 #14

Merged
jkeffects merged 5 commits from develop into main 2026-04-24 11:26:32 +00:00
Owner

update packages
fix: incident text time formating for berlin zone
fix: others listing excluding myself
package update and cve close

update packages fix: incident text time formating for berlin zone fix: others listing excluding myself package update and cve close
axios  1.0.0 - 1.14.0
Severity: moderate
Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF - https://github.com/advisories/GHSA-3p68-rc4w-qgx5
Axios has Unrestricted Cloud Metadata Exfiltration via Header Injection Chain - https://github.com/advisories/GHSA-fvcv-3m26-pcqx

follow-redirects  <=1.15.11
Severity: moderate
follow-redirects leaks Custom Authentication Headers to Cross-Domain Redirect Targets - https://github.com/advisories/GHSA-r4q5-vmmm-2653
Sign in to join this conversation.
No reviewers
No labels
bug
feature
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
FF-Admin/ff-operation-server!14
No description provided.