Security Vulnerability - Advisory URL #4072

Closed
opened 2026-02-28 03:50:15 -05:00 by deekerman · 1 comment
Owner

Originally created by @AstroFish849 on GitHub (Apr 7, 2025).

Originally assigned to: @louislam on GitHub.

GitHub Advisory URL for @louislam

https://github.com/louislam/uptime-kuma/security/advisories/GHSA-6fmm-2fvv-7mjh

Originally created by @AstroFish849 on GitHub (Apr 7, 2025). Originally assigned to: @louislam on GitHub. ### GitHub Advisory URL for @louislam https://github.com/louislam/uptime-kuma/security/advisories/GHSA-6fmm-2fvv-7mjh
deekerman 2026-02-28 03:50:15 -05:00
  • closed this issue
  • added the
    security
    label
Author
Owner

@louislam commented on GitHub (Apr 7, 2025):

Closed as it is from an upstream dependency and Uptime Kuma has never used Azure's feature.

Details
Path : /uptime-kuma/node_modules/@azure/identity/package.json
Installed version : 2.1.0
Fixed version : 3.1.1
https://nvd.nist.gov/vuln/detail/CVE-2023-36415

mssql -> tedious -> @azure/identity

@louislam commented on GitHub (Apr 7, 2025): Closed as it is from an upstream dependency and Uptime Kuma has never used Azure's feature. > Details Path : /uptime-kuma/node_modules/@azure/identity/package.json Installed version : 2.1.0 Fixed version : 3.1.1 https://nvd.nist.gov/vuln/detail/CVE-2023-36415 `mssql` -> `tedious` -> `@azure/identity`
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
starred/uptime-kuma#4072
No description provided.