package/chartjs: security bump to 2.9.4
authorJoeri Barbarien <joeri.barbarien@nokia.com>
Tue, 19 Jan 2021 15:46:05 +0000 (16:46 +0100)
committerPeter Korsgaard <peter@korsgaard.com>
Tue, 19 Jan 2021 17:56:51 +0000 (18:56 +0100)
commita20a86d7f6571849419f8920f0d1c56bcc4ec9c2
tree242c15a098a67ebab7ff0a90c56d116090fd9276
parent0244b11597461919d4240f9ee93dcb61a27e47d4
package/chartjs: security bump to 2.9.4

CVE-2020-7746 (https://nvd.nist.gov/vuln/detail/CVE-2020-7746)

    The options parameter is not properly sanitized when it is processed.
    When the options are processed, the existing options (or the defaults
    options) are deeply merged with provided options. However, during this
    operation, the keys of the object being set are not checked, leading to
    a prototype pollution.

Signed-off-by: Thomas De Schampheleire <thomas.de_schampheleire@nokia.com>
Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
package/chartjs/chartjs.hash
package/chartjs/chartjs.mk