Skip to content
This repository has been archived by the owner on Mar 25, 2020. It is now read-only.

High-severity security alert in dependency: ws #323

Open
soryy708 opened this issue Nov 9, 2019 · 0 comments
Open

High-severity security alert in dependency: ws #323

soryy708 opened this issue Nov 9, 2019 · 0 comments

Comments

@soryy708
Copy link

soryy708 commented Nov 9, 2019

The dependency ws is vulnerable in versions >= 0.2.6, < 3.3.1.
Patched version: 3.3.1.

Affected version of ws are vulnerable to: "a specially crafted value of the Sec-WebSocket-Extensions header that used Object.prototype property names as extension or parameter names could be used to make a ws server crash."

Fixing commit: websockets/ws@c4fe466

How to reproduce?

  1. Create a repository.
  2. npm install --save discord.io
  3. Upload to GitHub (including package-lock.json)
  4. See a "We found a potential security vulnerability in one of your dependencies." message at the github page of the repository (powered by WhiteSource)
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant