We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Windows 10
Rocket.Chat+ 2.10.2
I have tested with the latest application version
I can simulate the issue easily
Windows version comes with node.dll v7.9.0 which has a security issue (https://nodejs.org/en/blog/vulnerability/july-2017-security-releases/) Fixed version is 7.10.1
Node version with known security vulnerabilities used.
Node version with no known security vulnerabilities used.
I am not personally aware of specific ways to abuse this vulnerability. I just get alerts from our security software when users install Rocket.Chat.
The text was updated successfully, but these errors were encountered:
Thanks @JorisVanEijden I'll check the necessary updates to fix this.
Sorry, something went wrong.
@JorisVanEijden can you try the version 2.10.3?
2.10.3 ships with 7.9.0 too. 2.10.4 contains node 8.2.1 which is 3 security releases behind:
Again, I have no idea if any of these are actually exploitable in Rocket.Chat.
@JorisVanEijden please try version 2.10.5
2.10.5
2.10.5 also has node 8.2.1
No branches or pull requests
My Setup
Windows 10
Rocket.Chat+ 2.10.2
I have tested with the latest application version
I can simulate the issue easily
Description
Windows version comes with node.dll v7.9.0 which has a security issue (https://nodejs.org/en/blog/vulnerability/july-2017-security-releases/)
Fixed version is 7.10.1
Current Behavior
Node version with known security vulnerabilities used.
Expected Behavior
Node version with no known security vulnerabilities used.
Disclaimer
I am not personally aware of specific ways to abuse this vulnerability. I just get alerts from our security software when users install Rocket.Chat.
The text was updated successfully, but these errors were encountered: