Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Several CVE vulnerabilities in JsPolicy 0.2.2 #130

Open
jaredhancock31 opened this issue Jul 30, 2024 · 2 comments
Open

Several CVE vulnerabilities in JsPolicy 0.2.2 #130

jaredhancock31 opened this issue Jul 30, 2024 · 2 comments

Comments

@jaredhancock31
Copy link

As part of our image scanning we found that the latest JsPolicy (0.2.2) has several unaddressed CVEs

CVE ID: CVE-2023-26604,CVE-2023-50387
Vulnerabilities in libudev1

CVE-2023-42282 (MITRE NIST) Server-Side Request Forgery (SSRF) Vulnerability in ip 2.0.0
The ip package before 1.1.9 for Node.js might allow SSRF because some IP addresses (such as 0x7f.1) are improperly categorized as globally routable via isPublic.

CVE-2022-37434 (MITRE NIST) Out-of-bounds Write Vulnerability in zlib 1.2.11

CVE-2023-45853 (MITRE NIST) Integer Overflow or Wraparound Vulnerability in zlib 1.2.11

CVE-2021-4279 (MITRE NIST) Vulnerability in jsonpatch 2.2.0

CVE-2023-28154 (MITRE NIST) Vulnerability in webpack 5.75.0

@jaredhancock31 jaredhancock31 changed the title Several vulnerabilities in latest JsPolicy (0.2.2) Several vulnerabilities in JsPolicy 0.2.2 Jul 30, 2024
@jaredhancock31 jaredhancock31 changed the title Several vulnerabilities in JsPolicy 0.2.2 Several CVE vulnerabilities in JsPolicy 0.2.2 Jul 31, 2024
@abalamilla
Copy link

Any updates on this? It looks like the number of vulnerabilities is continuing to increase

@pavel-khritonenko
Copy link

Could anyone describe the status of the project? Published chart doesn't work in kubernetes 1.25+, vulnerabilities not fixed etc.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants