Skip to content

@angular-architects/module-federation version 15.0.3 security issue caused by semver 7.5.0 #344

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
gribakovs opened this issue Jul 25, 2023 · 4 comments · May be fixed by #831
Open

@angular-architects/module-federation version 15.0.3 security issue caused by semver 7.5.0 #344

gribakovs opened this issue Jul 25, 2023 · 4 comments · May be fixed by #831

Comments

@gribakovs
Copy link

Please ASAP upgrade semver to 7.5.2

There is vulnerability with CVE CVSS 3 severity of high/critical 7.5 level:

The semver package is vulnerable to Regular expression Denial of Service (ReDoS). Multiple functions and files listed below, fail to properly sanitize the range argument being provided by the user. An attacker, in some cases, can provide crafted inputs containing multiple whitespaces in the range, which when parsed by the package causes the regex engine to take longer, leading to a Denial of Service (DoS) condition.

More information is available in https://nvd.nist.gov/vuln/detail/CVE-2022-25883

@czareknster
Copy link

this same problem with 16.0.4

Screenshot 2023-08-01 at 15 47 05

@czareknster
Copy link

@manfredsteyer Can I ask you to deal with this?

@gribakovs
Copy link
Author

@manfredsteyer I would appreciate too if you could address issues related to CVE-2023-26115 and CVE-2022-25883.

@ofirrifo
Copy link

ofirrifo commented Sep 6, 2023

@manfredsteyer Any plan to fix it ?

@mguay22 mguay22 linked a pull request Apr 17, 2025 that will close this issue
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

3 participants