Yep 4.0.4 Fix -
: Includes fixes for libxml2 , libtiff , zlib , and gnutls to mitigate various memory and processing exploits. Recommended Actions for Developers
The following critical CVEs (Common Vulnerabilities and Exposures) have been patched in this version:
: Run a clean command (e.g., npm cache clean or your build system's equivalent) to prevent old, vulnerable artifacts from persisting. Yep 4.0.4 fix
If you are managing an environment using these packages, follow these remediation steps to ensure a clean update:
: Resolves three vulnerabilities (CVE-2022-30552, CVE-2022-33967, and CVE-2022-33103) impacting bootloader security. : Includes fixes for libxml2 , libtiff ,
: Fixes multiple vulnerabilities, including CVE-2021-3695 and CVE-2022-28733, which could potentially allow for unauthorized boot access.
: Addresses five separate security flaws (CVE-2021-3507 through CVE-2022-0358) related to virtualization and hardware emulation. : Fixes multiple vulnerabilities
: Patches CVE-2022-35252 to improve the security of data transfers.
