GithubHelp home page GithubHelp logo

Comments (14)

drewjenkins avatar drewjenkins commented on July 24, 2024 1

This still affects version 3.0.0 as well

from node-foreman.

vuesomedev avatar vuesomedev commented on July 24, 2024 1

@rmg How can we fix the npm audit error?

from node-foreman.

msakrejda avatar msakrejda commented on July 24, 2024 1

I just installed node-foreman and ran npm audit and I got no open advisories. It looks like https://www.npmjs.com/advisories/645 now notes "Upgrade to 3.0.1" is the fix @rmg so maybe this can just be closed?

from node-foreman.

phpfs avatar phpfs commented on July 24, 2024

Any updates to this?

from node-foreman.

rmg avatar rmg commented on July 24, 2024

I'm about to work on a fix for this, but in the mean time I'd like to list some of the mitigating factors involved so users can decide if they are affected by this or not.

This only affects the --forward feature, which is a development-time convenience feature for running a local http proxy that you can configure your browser to use.

If you're running this proxy in a publicly accessible manner then this vulnerability is probably the least of your concerns.

from node-foreman.

rmg avatar rmg commented on July 24, 2024

v3.0.1 has been published with a fix.

from node-foreman.

rmg avatar rmg commented on July 24, 2024

I'm at a loss as to how to update the vulnerability DBs 😞

It would also be nice to update the update the severity since "high" seems a little misleading considering you need to do something already considered dangerous (run a dev tool as a public open proxy) in order to even expose this.

from node-foreman.

Glutnix avatar Glutnix commented on July 24, 2024

Do you just email [email protected] or [email protected] ?

from node-foreman.

rmg avatar rmg commented on July 24, 2024

Snyk and HackerOne are not affiliated with npm/nsp so I'm not sure what they would be able to do about it.

from node-foreman.

fmagaldea avatar fmagaldea commented on July 24, 2024

This stills affects version 3.0.1 as well, here is "npm audit" report extract:
foreman_3 0 1_npm-audit

from node-foreman.

rmg avatar rmg commented on July 24, 2024

@fmagaldea that advisory is incorrect.

from node-foreman.

AmirBraham avatar AmirBraham commented on July 24, 2024

Any updates to this ? I get the vulnerability is fixed but it's still showing the advisory

from node-foreman.

rmg avatar rmg commented on July 24, 2024

I've sent an email to [email protected] to ask them to update the record.

from node-foreman.

Pilatch avatar Pilatch commented on July 24, 2024

When you do get that record updated, would you bump the version to 3.0.2 to make sure our random internal processes see it as a new artifact?

from node-foreman.

Related Issues (20)

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.