Update pac-resolver dependency due to critical security issue

Created on 20 September 2021, over 3 years ago
Updated 28 November 2024, 5 months ago

Problem/Motivation

Trivy reported a critical security alert on the pac-resolver library used in the drupal core. Could you please update yarn dependencies in a future release ?

var/www/html/web/core/yarn.lock (yarn)
======================================
Total: 1 (CRITICAL: 1)
+--------------+------------------+----------+-------------------+---------------+---------------------------------------+
| LIBRARY | VULNERABILITY ID | SEVERITY | INSTALLED VERSION | FIXED VERSION | TITLE |
+--------------+------------------+----------+-------------------+---------------+---------------------------------------+
| pac-resolver | CVE-2021-23406 | CRITICAL | 4.2.0 | 5.0.0 | nodejs-pac-resolver: remote |
| | | | | | code execution when used with |
| | | | | | untrusted input due to unsafe... |
| | | | | | -->avd.aquasec.com/nvd/cve-2021-23406 |
+--------------+------------------+----------+-------------------+---------------+---------------------------------------+

Proposed resolution

Upgrade pac-resolver to 5.0.0 version

📌 Task
Status

Closed: outdated

Version

11.0 🔥

Component

other

Created by

🇫🇷France b_billy

Live updates comments and jobs are added and updated live.
  • Security

    It is used for security vulnerabilities which do not need a security advisory. For example, security issues in projects which do not have security advisory coverage, or forward-porting a change already disclosed in a security advisory. See Drupal’s security advisory policy for details. Be careful publicly disclosing security vulnerabilities! Use the “Report a security vulnerability” link in the project page’s sidebar. See how to report a security issue for details.

Sign in to follow issues

Comments & Activities

Not all content is available!

It's likely this issue predates Contrib.social: some issue and comment data are missing.

Production build 0.71.5 2024