Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

jszip dependency 2.6.1 is vulnerable to attack CWE-29 #176

Open
Apobbot opened this issue Jan 13, 2023 · 6 comments
Open

jszip dependency 2.6.1 is vulnerable to attack CWE-29 #176

Apobbot opened this issue Jan 13, 2023 · 6 comments

Comments

@Apobbot
Copy link

Apobbot commented Jan 13, 2023

Hi, jszip 2.6.1 dependency is vulnerable to attack CWE-29.

Would be great to get a minor hotfix for this to avoid the vulnerability, if it doesn't impact the codebase much. The versions to update to would be 3.8.0, that doesn't have the vulnerability.

Thanks.

@kant2002
Copy link
Collaborator

Technically you have 2.7.0 now, but it is still has this vuln. I submit PR Stuk/jszip#884 to backport fix, so hopefully this get accepted, so I can re-release secured version.

@jmac105
Copy link

jmac105 commented Feb 7, 2023

jszip < 3.8.0 has now had a critical (9.8/10) vulnerability disclosed GHSA-36fh-84j7-cv5h

Could you update jszip to latest version to resolve these?

@kant2002
Copy link
Collaborator

kant2002 commented Feb 7, 2023

Ping me in couple days, if there would be no response from JSzip I would publish with forked package.

@aslubsky
Copy link

@kant2002 is there any chance to publish this fixes to npm?

@kant2002
Copy link
Collaborator

@aslubsky and others, I update version to 1.4.1 where I switch to fork of [email protected] which does not have security issues. I start looking for alternatives to jszip with both sync and async API, so I can provide async API without breaking changes. Let me know if you know such alternatives.

@aslubsky
Copy link

Thanks a lot! We also use jszip on current project, but on my pet-project I've used pizzip, take a look ot it.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants