-
Notifications
You must be signed in to change notification settings - Fork 47
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Various vulnerabilities #196
Comments
Just noticed that #195 is in fact also addressing part of the CVE above. |
Hi @AdrienFromToulouse - we've merged the PR bumping express to 4.21 and openapi to upstream from wesleytodd, from the CVE, it now looks like we're using a new enough version. I'll cut a patch release of the proxy |
1.4.7 is now out, updated to upstream openapi and express 4.21, which from my quick check using |
@chriswk thank you so much for your help! will deploy asap. |
I think those are the only CVE left: |
That's odd, GHSA-qw6h-vgh9-j6wx says < 4.20, and we just upgraded express to 4.21 |
Agreed it is strange, however it still appears on their repo too, so I guess there might be something missing on their end: GHSA-qw6h-vgh9-j6wx
We run the latest docker image though... Will triple check on my end. |
That's very strange, the image looks indeed all good according to
|
@chriswk sorry we may have to add that new one into the mix too: It is a low severity one. |
Hi @AdrienFromToulouse #199 is made to setup resolution to the just released 1.0.0 of |
Awesome 🚀 , if one day I stop by Oslo, I will offer you a coffee per release versions you did on that issue. |
Hehe. No need. This is in our interest as well. If you're in Oslo I'll buy you a alcoholic/non-alcoholic drink of your choice for your patience and complete bug reports. :) |
1.4.8 is released and getting pushed as we speak. I've made Unleash/helm-charts#169 to make sure our helm chart is also up to date. Closing this issue now. Feel free to create new issues if you start having problems again. |
Describe the bug
Hi there,
multiple CVEs with fix are available:
CVE-2024-43800
CVE-2024-43796
CVE-2024-43799
CVE-2024-45296
Would you mind upgrading the docker image? 🙏
Cheers,
Steps to reproduce the bug
No response
Expected behavior
No response
Logs, error output, etc.
No response
Screenshots
No response
Additional context
No response
Unleash version
v1.4.6
Subscription type
Pro
Hosting type
Self-hosted
SDK information (language and version)
No response
The text was updated successfully, but these errors were encountered: