-
Notifications
You must be signed in to change notification settings - Fork 110
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Netmask security vulnerability #124
Comments
This is blocking us as well. |
You are referring to Non official library , which has the issue. I am using this official library which doesn't have any security vulnerability. |
getting same vulnerability |
I must push back against your screen shot and ask for context. Because this vulnerability is very real and can be reproduced. Attempting to force the audit fix with both
zac@smg-macmini:~/Projects
> mkdir mailgun
zac@smg-macmini:~/Projects
> cd mailgun/
zac@smg-macmini:~/Projects/mailgun
> npm init
This utility will walk you through creating a package.json file.
It only covers the most common items, and tries to guess sensible defaults.
See `npm help init` for definitive documentation on these fields
and exactly what they do.
Use `npm install <pkg>` afterwards to install a package and
save it as a dependency in the package.json file.
Press ^C at any time to quit.
package name: (mailgun)
version: (1.0.0)
description:
entry point: (index.js)
test command:
git repository:
keywords:
author:
license: (ISC)
About to write to /Users/zac/Projects/mailgun/package.json:
{
"name": "mailgun",
"version": "1.0.0",
"description": "",
"main": "index.js",
"scripts": {
"test": "echo \"Error: no test specified\" && exit 1"
},
"author": "",
"license": "ISC"
}
Is this OK? (yes)
zac@smg-macmini:~/Projects/mailgun
> npm install mailgun-js
added 85 packages, and audited 86 packages in 2s
5 high severity vulnerabilities
To address all issues, run:
npm audit fix
Run `npm audit` for details.
zac@smg-macmini:~/Projects/mailgun
> npm audit
# npm audit report
netmask <2.0.1
Severity: high
netmask npm package vulnerable to octal input data - https://npmjs.com/advisories/1658
fix available via `npm audit fix --force`
Will install [email protected], which is a breaking change
node_modules/netmask
pac-resolver <=4.1.0
Depends on vulnerable versions of netmask
node_modules/pac-resolver
pac-proxy-agent <=3.0.1
Depends on vulnerable versions of pac-resolver
node_modules/pac-proxy-agent
proxy-agent 1.1.0 - 3.1.1
Depends on vulnerable versions of pac-proxy-agent
node_modules/proxy-agent
mailgun-js >=0.6.8
Depends on vulnerable versions of proxy-agent
node_modules/mailgun-js
5 high severity vulnerabilities
To address all issues (including breaking changes), run:
npm audit fix --force
zac@smg-macmini:~/Projects/mailgun
> npm audit fix
up to date, audited 86 packages in 942ms
# npm audit report
netmask <2.0.1
Severity: high
netmask npm package vulnerable to octal input data - https://npmjs.com/advisories/1658
fix available via `npm audit fix --force`
Will install [email protected], which is a breaking change
node_modules/netmask
pac-resolver <=4.1.0
Depends on vulnerable versions of netmask
node_modules/pac-resolver
pac-proxy-agent <=3.0.1
Depends on vulnerable versions of pac-resolver
node_modules/pac-proxy-agent
proxy-agent 1.1.0 - 3.1.1
Depends on vulnerable versions of pac-proxy-agent
node_modules/proxy-agent
mailgun-js >=0.6.8
Depends on vulnerable versions of proxy-agent
node_modules/mailgun-js
5 high severity vulnerabilities
To address all issues (including breaking changes), run:
npm audit fix --force
zac@smg-macmini:~/Projects/mailgun
> npm audit fix --force
npm WARN using --force Recommended protections disabled.
npm WARN audit Updating mailgun-js to 0.6.7,which is a SemVer major change.
npm WARN deprecated [email protected]: scmp v2 uses improved core crypto comparison since Node v6.6.0
added 3 packages, removed 76 packages, changed 7 packages, and audited 13 packages in 2s
# npm audit report
debug <=2.6.8 || 3.0.0 - 3.0.1
Regular Expression Denial of Service - https://npmjs.com/advisories/534
fix available via `npm audit fix --force`
Will install [email protected], which is a breaking change
node_modules/debug
mailgun-js 0.4.2 - 0.9.1
Depends on vulnerable versions of debug
Depends on vulnerable versions of form-data
node_modules/mailgun-js
mime <=1.4.0 || 2.0.1 - 2.0.2
Severity: moderate
Regular Expression Denial of Service - https://npmjs.com/advisories/535
fix available via `npm audit fix --force`
Will install [email protected], which is a breaking change
node_modules/mime
form-data 0.0.2 - 0.1.4
Depends on vulnerable versions of mime
node_modules/form-data
mailgun-js 0.4.2 - 0.9.1
Depends on vulnerable versions of debug
Depends on vulnerable versions of form-data
node_modules/mailgun-js
4 vulnerabilities (1 low, 3 moderate)
To address all issues (including breaking changes), run:
npm audit fix --force
|
Sorry for the noise. I could reproduce what @zacharytyhacz did but I think we are talking to another repository: |
Hello @zacharytyhacz |
This dependency now has a
High
security rating from npm https://npmjs.com/advisories/1658Due to the number of linked dependencies that ultimately import netmask, it is hard to say if there would be any unforeseen breakage with imported the patched version of
>=2.0.1
.The text was updated successfully, but these errors were encountered: