← All tasks
javascriptwebpack/webpack-dev-server #4167Not a task: already works

Upstream Prototype Pollution vulnerability from selfsigned 1.10.11 -> node-forge 0.10.0

envgap__webpack__webpack-dev-server-4167

01 / FAILURE SIGNATURE

As reported upstream

No identifying execution failure has been captured.
Not a benchmark task.
  • The project already builds and runs before the fix, so there is nothing to repair.

02 / ENVIRONMENT RECIPE

Base commit
c1907f15d20787c1dede0cf62d559bbdf6878cd5
Manifest
package.json
Reproduce
Awaiting issue-specific recipe
Run under trace
Awaiting a meaningful runtime command

03 / ORIGINAL ISSUE TEXT

webpack/webpack-dev-server #4167 · read the original issue
<!-- Please don't delete this template otherwise your issue will be closed immediately -->

<!-- Before creating an issue please make sure you are using the latest version of webpack. -->



### Bug report



<!-- Please ask questions on discussions, StackOverflow or the webpack Gitter. -->

<!-- https://github.com/webpack/webpack/discussions -->

<!-- https://stackoverflow.com/questions/ask?tags=webpack -->

<!-- https://gitter.im/webpack/webpack -->

<!-- Issues which contain questions or support requests will be closed. -->



There is an open CVE for `node-forge` 0.10.0, which webpack-dev-server includes via `selfsigned` 1.10.11. 

- https://github.com/advisories/GHSA-5rrq-pxf6-6jx5

- https://github.com/advisories/GHSA-gf8q-jrpm-jvxq



Updating to `selfsigned` 1.10.13 will address the issue and is a backwards compatible update. This was attempted to be fixed in https://github.com/webpack/webpack-dev-server/pull/4162 by @wcedmisten-reify, but they could not sign the CLA. Setting up issue for another contributor who can make the change.



### Actual Behavior



<!-- Explain exactly how it behave -->

Message from dependabot about the security issue:

```

The latest possible version that can be installed is 0.10.0 because of the following conflicting dependency:

webpack-dev-server@4.7.2 requires node-forge@^0.10.0 via selfsigned@1.10.11

The earliest fixed version is 1.0.0.

```



### Expected Behavior



<!-- "It should work" is not a helpful explanation -->

<!-- Explain exactly how it should behave -->

N/A



### How Do We Reproduce?



<!-- A great way to do this is to provide your configuration via a GitHub repository -->

<!-- The most helpful is a minimal reproduction with instructions on how to reproduce -->

<!-- Repositories with too many files or large `webpack.config.js` files are not suitable -->

<!-- Please only add small code snippets directly into this issue -->

<!-- https://gist.github.com is a good place for longer code snippets -->

<!-- If your issue is caused by a plugin or loader, please create an issue on the loader/plugin repository instead -->



N/A



### Please paste the results of `npx webpack-cli info` here, and mention other relevant information

Continue on GitHub ↗

04 / LABELS

Labels from the report text only; not yet run

No supported category has been assigned.

Label rules and the text that matched
[]