Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Node.dll insecure version #659

Closed
2 tasks done
JorisVanEijden opened this issue Feb 1, 2018 · 5 comments
Closed
2 tasks done

Node.dll insecure version #659

JorisVanEijden opened this issue Feb 1, 2018 · 5 comments

Comments

@JorisVanEijden
Copy link

My Setup

  • Windows 10

  • Rocket.Chat+ 2.10.2

  • I have tested with the latest application version

  • I can simulate the issue easily

Description

Windows version comes with node.dll v7.9.0 which has a security issue (https://nodejs.org/en/blog/vulnerability/july-2017-security-releases/)
Fixed version is 7.10.1

Current Behavior

Node version with known security vulnerabilities used.

Expected Behavior

Node version with no known security vulnerabilities used.

Disclaimer

I am not personally aware of specific ways to abuse this vulnerability. I just get alerts from our security software when users install Rocket.Chat.

@gdelavald
Copy link
Contributor

Thanks @JorisVanEijden I'll check the necessary updates to fix this.

@engelgabriel
Copy link
Member

@JorisVanEijden can you try the version 2.10.3?

@JorisVanEijden
Copy link
Author

JorisVanEijden commented Feb 6, 2018

2.10.3 ships with 7.9.0 too.
2.10.4 contains node 8.2.1 which is 3 security releases behind:

Again, I have no idea if any of these are actually exploitable in Rocket.Chat.

@engelgabriel
Copy link
Member

@JorisVanEijden please try version 2.10.5

@JorisVanEijden
Copy link
Author

2.10.5 also has node 8.2.1

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

4 participants