Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Critical vulnerability - Formidable arbitrary file upload #2167

Closed
ayemelyanenko-chegg opened this issue Apr 24, 2024 · 5 comments
Closed

Critical vulnerability - Formidable arbitrary file upload #2167

ayemelyanenko-chegg opened this issue Apr 24, 2024 · 5 comments

Comments

@ayemelyanenko-chegg
Copy link

Description

There is a critical vulnerability for the @newrelic/publish-sourcemap library and it's getting picked up by our security scans and could become a blocker as the scans could block the ability to deploy. I know that this might not be the right place for the bug report but I was not able to find the right repository on Github in order to file this issue. Perhaps someone can help in reaching the team responsible for maintaining @newrelic/publish-sourcemap?

Screenshot 2024-04-24 at 2 09 01 PM

Expected Behavior

Vulnerability should be patched by updating formidable dependency to >=3.2.4

Troubleshooting or NR Diag results

Steps to Reproduce

Install @newrelic/publish-sourcemap package and run npm or yarn audit to get the critical violation report

Your Environment

  • ex: Browser name and version:
  • ex: Node version:
  • ex: Operating System and version:

Additional context

https://www.npmjs.com/advisories/1097147

@workato-integration
Copy link

@workato-integration workato-integration bot changed the title Critical vulnerability - Formidable arbitrary file upload Critical vulnerability - Formidable arbitrary file upload Apr 24, 2024
@bizob2828
Copy link
Member

Hi. Yes, we don't own this but I'll try to find out who does internally and move this issue to the appropriate place.

@ayemelyanenko-chegg
Copy link
Author

Hi, thanks @bizob2828

@worc
Copy link

worc commented Apr 25, 2024

CVE-2022-29622 was revoked by Snyk, but does still appear in other vulnerability databases as the NVD themselves never revoked their entry.

The contributors over on formidable had a long thread about this vulnerability a couple years ago. The general opinion over there seems to be that the vulnerability was filed in error. But there was an open question if the vulnerability was completely invalid or if it was valid, but actually at a lower risk level.

For us, I don't see a need to dive any deeper into the issue. Our version of formidable is out of date, and we will update it in an upcoming release of @newrelic/publish-sourcemap—likely it will be version 5.1.2.

@bizob2828 bizob2828 moved this to Done: Issues recently completed in Node.js Engineering Board Jul 15, 2024
@worc
Copy link

worc commented Oct 2, 2024

Vulnerability resolved in [email protected]

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
Archived in project
Development

No branches or pull requests

3 participants