Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Remote Memory Exposure in [email protected] > [email protected] > [email protected] #48

Closed
kohms opened this issue Jun 30, 2017 · 9 comments

Comments

@kohms
Copy link

kohms commented Jun 30, 2017

Hi,

I am checking my projects with nsp and get the following findings.

selection_010

Could you please update dependencies or remove the follow module if possible?
It looks like that the project is no longer active, the same issue was reported on Jun 10, 2016 at the follow project iriscouch/follow#84.
The last commit on master was on May 24, 2015.

https://nodesecurity.io/advisories/309
https://nodesecurity.io/advisories/77

Thanks in advance
Konrad

@janl
Copy link
Member

janl commented Jul 5, 2017

Should we switch to cloudant-follow? https://github.com/cloudant-labs/cloudant-follow

@janl
Copy link
Member

janl commented Jul 5, 2017

PR here: #51

@kohms
Copy link
Author

kohms commented Jul 5, 2017

Cool thanks for figuring that out.
👍 for PR #51

@kohms
Copy link
Author

kohms commented Jul 6, 2017

@dscape could you have a look please?

@dscape
Copy link
Contributor

dscape commented Jul 26, 2017

I can have a look, but since I'm no longer a maintainer would be good to understand what the scope is! Appreciate the feedback

@loay
Copy link
Contributor

loay commented Sep 13, 2017

@dscape
There are security vulnerabilities.

(+) 2 vulnerabilities found
 Name      Installed   Patched                      Path                                                       More Info                              
 request   2.55.0      >=2.68.0                     [email protected] > [email protected] > [email protected]                https://nodesecurity.io/advisories/309 
 hawk      2.3.1       >=3.1.3 < 4.0.0 || >=4.1.1   [email protected] > [email protected] > [email protected] > [email protected]   https://nodesecurity.io/advisories/77  

Even if we update to the last version of follow, it won't fix the issue, since follow is using an outdated versions of request and hawk .. so we need follow to update or to use another library instead of follow.

@loay
Copy link
Contributor

loay commented Sep 19, 2017

The related pr is being merged: #51
Can the release team let us know when it will be released so the security changes take effect? Thank you

@garrensmith
Copy link
Member

6.4.2 fixes this

@kohms
Copy link
Author

kohms commented Sep 21, 2017

Thanks for fixing :-)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

5 participants