minimist before 1.2.2 could be tricked into adding or modifying properties of Object.prototype using a "constructor" or "__proto__" payload.
CVE: (none) => CVE-2020-7598
Whiteboard: (none) => MGA7TOOStatus comment: (none) => Fixed upstream in 1.2.2Summary: minimist security issue CVE-2020-7598 => nodejs-minimist new security issue CVE-2020-7598
A nobody package, assigning globally. CC'd other nodejs packagers.
CC: (none) => joequant, ouaurelien, smelrorAssignee: bugsquad => pkg-bugs
new version 1.2.5 pushed in cauldron.
Version: Cauldron => 7Whiteboard: MGA7TOO => (none)CC: (none) => mageia
https://blog.mageia.org/en/2021/06/08/mageia-7-will-reach-end-of-support-on-30th-of-june-the-king-is-dead-long-live-the-king/
Resolution: (none) => OLDStatus: NEW => RESOLVED