Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

fix(cmd-socketio-server): fix Prototype Pollution in nconf #2684

Closed
petermetz opened this issue Sep 11, 2023 · 2 comments
Closed

fix(cmd-socketio-server): fix Prototype Pollution in nconf #2684

petermetz opened this issue Sep 11, 2023 · 2 comments
Assignees
Labels
bug Something isn't working dependencies Pull requests that update a dependency file dependent good-first-issue Good for newcomers good-first-issue-200-intermediate Hacktoberfest Hacktoberfest participants are welcome to take a stab at issues marked with this label. P2 Priority 2: High Security Related to existing or potential security vulnerabilities
Milestone

Comments

@petermetz
Copy link
Contributor

Description

CVE ID
: CVE-2022-21803
GHSA ID: GHSA-6xwr-q98w-rvg7

https://github.com/hyperledger/cacti/security/dependabot/131

See advisory in GitHub Advisory Database

Depends on #2563

This can't be completely fixed until the above linked PR/issue is also resolved because an old version of nconf is being used by the old version of the Fabric NodeJS libraries (which is being resolved by the parent PR/issue)

@petermetz petermetz added bug Something isn't working good-first-issue Good for newcomers dependencies Pull requests that update a dependency file Security Related to existing or potential security vulnerabilities Hacktoberfest Hacktoberfest participants are welcome to take a stab at issues marked with this label. good-first-issue-200-intermediate P2 Priority 2: High labels Sep 11, 2023
@petermetz petermetz added this to the v2.0.0 milestone Sep 11, 2023
@petermetz petermetz self-assigned this Sep 11, 2023
@github-actions
Copy link

This PR/issue depends on:

petermetz added a commit to petermetz/cacti that referenced this issue Sep 11, 2023
Depends on hyperledger-cacti#2562 - build(deps): fix npm (grpc) build on NodeJS v20.4.0

Fixes hyperledger-cacti#2684

Signed-off-by: Peter Somogyvari <peter.somogyvari@accenture.com>
@petermetz petermetz moved this from In Progress to In review in Cacti_Scrum_Project_v2_Release Sep 11, 2023
sandeepnRES pushed a commit to petermetz/cacti that referenced this issue Sep 20, 2023
Depends on hyperledger-cacti#2562 - build(deps): fix npm (grpc) build on NodeJS v20.4.0

Fixes hyperledger-cacti#2684

Signed-off-by: Peter Somogyvari <peter.somogyvari@accenture.com>
petermetz added a commit to petermetz/cacti that referenced this issue Oct 16, 2023
Depends on hyperledger-cacti#2562 - build(deps): fix npm (grpc) build on NodeJS v20.4.0

Fixes hyperledger-cacti#2684

[skip ci]

Signed-off-by: Peter Somogyvari <peter.somogyvari@accenture.com>
@petermetz
Copy link
Contributor Author

Fixed in another change as explained by #2685 (comment)

@petermetz petermetz closed this as not planned Won't fix, can't repro, duplicate, stale Nov 28, 2023
@github-project-automation github-project-automation bot moved this from In review to Done in Cacti_Scrum_Project_v2_Release Nov 28, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working dependencies Pull requests that update a dependency file dependent good-first-issue Good for newcomers good-first-issue-200-intermediate Hacktoberfest Hacktoberfest participants are welcome to take a stab at issues marked with this label. P2 Priority 2: High Security Related to existing or potential security vulnerabilities
Projects
None yet
Development

Successfully merging a pull request may close this issue.

1 participant