Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

wrangler Depends on vulnerable versions of miniflare #1679

Closed
Vladi-ed opened this issue Aug 15, 2022 · 3 comments · Fixed by #1691 or #1719
Closed

wrangler Depends on vulnerable versions of miniflare #1679

Vladi-ed opened this issue Aug 15, 2022 · 3 comments · Fixed by #1691 or #1719
Assignees
Labels
maintenance Maintenance task

Comments

@Vladi-ed
Copy link

Wrangler 2.0.25

npm audit report

undici <5.8.0
Severity: moderate
undici before v5.8.0 vulnerable to CRLF injection in request headers - GHSA-3cvr-822r-rqcc
No fix available
node_modules/undici
@miniflare/cache *
Depends on vulnerable versions of undici
node_modules/@miniflare/cache
@miniflare/core *
Depends on vulnerable versions of undici
node_modules/@miniflare/core
@miniflare/scheduler *
Depends on vulnerable versions of @miniflare/core
node_modules/@miniflare/scheduler
@miniflare/durable-objects *
Depends on vulnerable versions of undici
node_modules/@miniflare/durable-objects
@miniflare/html-rewriter *
Depends on vulnerable versions of undici
node_modules/@miniflare/html-rewriter
@miniflare/http-server *
Depends on vulnerable versions of undici
node_modules/@miniflare/http-server
@miniflare/r2 *
Depends on vulnerable versions of undici
node_modules/@miniflare/r2
miniflare >=2.0.0-next.1
Depends on vulnerable versions of @miniflare/r2
Depends on vulnerable versions of undici
node_modules/miniflare
wrangler *
Depends on vulnerable versions of miniflare
node_modules/wrangler
@miniflare/web-sockets *
Depends on vulnerable versions of undici
node_modules/@miniflare/web-sockets

@cameron-robey cameron-robey self-assigned this Aug 15, 2022
@cameron-robey cameron-robey added the maintenance Maintenance task label Aug 15, 2022
@cameron-robey
Copy link
Contributor

Will require increasing the minimum supported node version to >= 16.8.0
Will create a pr today, just might need to think carefully when we land

@lrapoport-cf lrapoport-cf moved this to Untriaged in workers-sdk Aug 15, 2022
@cameron-robey
Copy link
Contributor

cloudflare/miniflare#333

Miniflare pr

@cameron-robey
Copy link
Contributor

Unidici is also a dependency of wrangler itself, need to fix for that too

@cameron-robey cameron-robey moved this from Untriaged to In Progress in workers-sdk Aug 15, 2022
Repository owner moved this from In Progress to Done in workers-sdk Aug 22, 2022
Repository owner moved this from In Progress to Done in workers-sdk Aug 22, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
maintenance Maintenance task
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants