Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

dependency mime ~1.3.4 has a ReDoS vulnerability #90

Closed
pmuellr opened this issue Oct 4, 2017 · 2 comments
Closed

dependency mime ~1.3.4 has a ReDoS vulnerability #90

pmuellr opened this issue Oct 4, 2017 · 2 comments

Comments

@pmuellr
Copy link
Contributor

pmuellr commented Oct 4, 2017

see: https://snyk.io/vuln/npm:mime:20170907

Hopefully this is a simple update of the dependency, will take a look soon.

pmuellr pushed a commit to pmuellr/st that referenced this issue Oct 4, 2017
fixes issue isaacs#90

Info on the vulnerability: https://snyk.io/vuln/npm:mime:20170907

Versions of mime < 1.4.1 are vulnerable.

Upgraded from ~1.3.4 to ~1.4.1
@dyaa
Copy link

dyaa commented Oct 6, 2017

As nodesecurity's Remediation

Please upgrade to version 2.0.3 or greater

https://nodesecurity.io/advisories/535

@pmuellr
Copy link
Contributor Author

pmuellr commented Oct 6, 2017

Please upgrade to version 2.0.3 or greater

The PR ref'd here - #91 - only upgrades to ~1.4.1 since presumably there's less API surface change between this and 2.0.3 (without having to investigate too deeply).

The NSP page ref'd does say to upgrade to >= 2.0.3 in the big "Remediation" section, but in the top left also says:

Vulnerable: < 1.4.1 || > 2.0.0 < 2.0.3
Patched: >= 1.4.1 < 2.0.0 || >= 2.0.3

rvagg pushed a commit that referenced this issue Oct 9, 2017
fixes issue #90

Info on the vulnerability: https://snyk.io/vuln/npm:mime:20170907

Versions of mime < 1.4.1 are vulnerable.

Upgraded from ~1.3.4 to ~1.4.1
@rvagg rvagg closed this as completed Nov 11, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants