Skip to content

Releases: yahoo/express-busboy

v10.1.0

23 May 21:32
Compare
Choose a tag to compare
  • feat: add an option to disable body parsing #41

v10.0.0

09 May 14:21
Compare
Choose a tag to compare
  • fix: use md5 hash for filename to avoid path traversal vulnerability #40

v9.0.0

23 May 20:48
Compare
Choose a tag to compare
  • chore: upgrade to latest connect-busboy (#34) f5936f8
express-busboy@8.0.2 > connect-busboy@0.0.3 > busboy@0.3.1 > dicer@0.3.0 -- [CVE-2022-24434](https://nvd.nist.gov/vuln/detail/CVE-2022-24434) This affects all versions of package dicer.
A malicious attacker can send a modified form to server, and crash the nodejs service. An attacker could sent the payload again and again so that the service continuously crashes.

v8.0.2...v9.0.0

v8.0.2

30 Mar 03:03
Compare
Choose a tag to compare

v8.0.1...v8.0.2

v8.0.1

21 Mar 15:00
Compare
Choose a tag to compare
  • chore: upgrade mkdirp dependency (#29) 0ac7986
  • Merge pull request #27 from mattlljones/name-fix 6455b51

v7.0.1...v8.0.1