Upstream Prototype Pollution vulnerability from selfsigned 1.10.11 -> node-forge 0.10.0
envgap__webpack__webpack-dev-server-4167
01 / FAILURE SIGNATURE
As reported upstream
No identifying execution failure has been captured.
Not a benchmark task.
- The project already builds and runs before the fix, so there is nothing to repair.
02 / ENVIRONMENT RECIPE
- Base commit
c1907f15d20787c1dede0cf62d559bbdf6878cd5- Manifest
package.json- Reproduce
Awaiting issue-specific recipe- Run under trace
Awaiting a meaningful runtime command
03 / ORIGINAL ISSUE TEXT
webpack/webpack-dev-server #4167 · read the original issue
<!-- Please don't delete this template otherwise your issue will be closed immediately --> <!-- Before creating an issue please make sure you are using the latest version of webpack. --> ### Bug report <!-- Please ask questions on discussions, StackOverflow or the webpack Gitter. --> <!-- https://github.com/webpack/webpack/discussions --> <!-- https://stackoverflow.com/questions/ask?tags=webpack --> <!-- https://gitter.im/webpack/webpack --> <!-- Issues which contain questions or support requests will be closed. --> There is an open CVE for `node-forge` 0.10.0, which webpack-dev-server includes via `selfsigned` 1.10.11. - https://github.com/advisories/GHSA-5rrq-pxf6-6jx5 - https://github.com/advisories/GHSA-gf8q-jrpm-jvxq Updating to `selfsigned` 1.10.13 will address the issue and is a backwards compatible update. This was attempted to be fixed in https://github.com/webpack/webpack-dev-server/pull/4162 by @wcedmisten-reify, but they could not sign the CLA. Setting up issue for another contributor who can make the change. ### Actual Behavior <!-- Explain exactly how it behave --> Message from dependabot about the security issue: ``` The latest possible version that can be installed is 0.10.0 because of the following conflicting dependency: webpack-dev-server@4.7.2 requires node-forge@^0.10.0 via selfsigned@1.10.11 The earliest fixed version is 1.0.0. ``` ### Expected Behavior <!-- "It should work" is not a helpful explanation --> <!-- Explain exactly how it should behave --> N/A ### How Do We Reproduce? <!-- A great way to do this is to provide your configuration via a GitHub repository --> <!-- The most helpful is a minimal reproduction with instructions on how to reproduce --> <!-- Repositories with too many files or large `webpack.config.js` files are not suitable --> <!-- Please only add small code snippets directly into this issue --> <!-- https://gist.github.com is a good place for longer code snippets --> <!-- If your issue is caused by a plugin or loader, please create an issue on the loader/plugin repository instead --> N/A ### Please paste the results of `npx webpack-cli info` here, and mention other relevant information
04 / LABELS
Labels from the report text only; not yet run
No supported category has been assigned.
Label rules and the text that matched
[]