Skip to content
This repository has been archived by the owner on Mar 23, 2023. It is now read-only.

CVE-2020-15168 found in [email protected] #504

Closed
leonidio-com opened this issue Sep 18, 2020 · 13 comments · Fixed by #507
Closed

CVE-2020-15168 found in [email protected] #504

leonidio-com opened this issue Sep 18, 2020 · 13 comments · Fixed by #507

Comments

@leonidio-com
Copy link

CVE-2020-15168 found in [email protected]
CVE-2020-15168 is fixed in "node-fetch": "^2.6.1"
Is there a chance to update it in flux?
+-- [email protected]
| +-- [email protected]
| | -- [email protected] deduped | -- [email protected]
| +-- [email protected]
| +-- [email protected]
| | +-- [email protected]

@jigalovd
Copy link

jigalovd commented Oct 1, 2020

we have same issue with [email protected]
image
any update?

@TomBrien
Copy link

TomBrien commented Oct 5, 2020

facebook/docusaurus also has this vulnerability for the same reason. Bumping fbjs (currently two major versions behind) would fix

@hugoboos
Copy link

hugoboos commented Oct 7, 2020

Appreciated if this is fixed.

@Kenzku
Copy link

Kenzku commented Dec 14, 2020

Hej, I saw the release number is still 3.1.3 but that was nearly 3 years ago. Any plan for a minor release please?

@yangshun
Copy link
Contributor

Yeah we'll try to make a release this week.

@janetwang1
Copy link

Yeah we'll try to make a release this week.

any update on this issue? will you be able to make a release soon?

Thanks

Janet

@yangshun
Copy link
Contributor

yangshun commented Jan 5, 2021

It has been released

@Kenzku
Copy link

Kenzku commented Jan 5, 2021

@yangshun how about this: facebook/fbjs#412

@leonidio-com
Copy link
Author

@yangshun
I am still seeing this here:

I was thinking the whole point of this issue was to make node-fetch >= 2.6.1
Is there a chance we could address that?

@yangshun
Copy link
Contributor

yangshun commented Jan 8, 2021

We need fbemitter to upgrade the fbjs version it uses but it has already been archived. I'll see what I can do internally to maybe upgrade fbemitter.

@yangshun yangshun reopened this Jan 8, 2021
@Kenzku
Copy link

Kenzku commented Jan 8, 2021

@yangshun Thanks for investigating on it

@yangshun
Copy link
Contributor

yangshun commented Jan 9, 2021

I got fbemitter unarchived, upgraded deps and published v3.0.0. Then I updated flux to use [email protected] and released v4.0.1.

Should be fine now!

@yangshun yangshun closed this as completed Jan 9, 2021
@Kenzku
Copy link

Kenzku commented Jan 9, 2021

@yangshun thanks so much. I will sync up with my team the next working day.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

7 participants