Yep 4.0.4 — Fix
If you are managing an environment using these packages, follow these remediation steps to ensure a clean update:
: Run a clean command (e.g., npm cache clean or your build system's equivalent) to prevent old, vulnerable artifacts from persisting. Yep 4.0.4 fix
: Resolves three vulnerabilities (CVE-2022-30552, CVE-2022-33967, and CVE-2022-33103) impacting bootloader security. If you are managing an environment using these
The following critical CVEs (Common Vulnerabilities and Exposures) have been patched in this version: including CVE-2021-3695 and CVE-2022-28733
: Fixes CVE-2022-35737 to prevent potential crashes or data corruption during database operations.
: Fixes multiple vulnerabilities, including CVE-2021-3695 and CVE-2022-28733, which could potentially allow for unauthorized boot access.