browserify / browserify/static-module
Problem with IQ Server vulnerability : sonatype-2020-0067
- Langage dominant
- JavaScript
- Étoiles
- 75
- Forks
- 22
- Métriques de merge des PR
- Aucune PR mergée en 30 j
Description
Hi,
Here is my problem.
I want to install "compodoc" in an internal angular project but one dependencies is blocked by Iq server for this reason :
Sonatype-2020-0067 :
**EXPLANATION**
The acorn package is vulnerable to Regular Expression Denial of Service (ReDoS). The RegExpValidationState.prototype.at and RegExpValidationState.prototype.nextIndex functions in acorn.js, acorn.mjs, and acorn.es.js process user-supplied input without properly validating UTF-16 surrogate pairs. A remote attacker can exploit this behavior by submitting a crafted UTF-16 encoded string which, when parsed by the application, will result in an infinite loop, ultimately leading to a DoS condition.
**ROOT CAUSE**
static-module-3.0.4.tgzpackage/dist/acorn.js[5.5.0, 5.7.4)
**ADVISORIES**
Third Party:https://www.npmjs.com/advisories/1488
Is there a solution to fix it in futur version of "static module" ?
Best regards
Guide de contribution
Aucun guide de contribution indexé pour ce dépôt
Piste de recherche
Inspectez static-module-3.0.4.tgz ainsi que ses chemins dist/acorn.js, acorn.mjs et acorn.es.js inclus ; commencez par vérifier comment la version signalée d’acorn entre dans l’arbre des dépendances et comparez-la avec l’advisory associé. Le travail sera considéré comme terminé lorsqu’une résolution de dépendance confirmée par un maintainer supprimera la plage vulnérable signalée tout en conservant static-module utilisable.
Rédigé par le modèle d'indexation à partir du texte de l'issue.
Évaluation
- Stack technique
- javascript
- Domaine
- security, tooling
- Type d'issue
- Bug
- Difficulté
- 4/5
- Temps estimé
- 3-5 jours
- Activité
- À l'abandon
- Clarté
- À clarifier
- Accessibilité débutants
- 20/100