Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security Vulnerabilities - Request to update express version from 4.19.2 to 4.21.1 #1412

Open
tblauer opened this issue Nov 8, 2024 · 2 comments

Comments

@tblauer
Copy link

tblauer commented Nov 8, 2024

When running anchor and trivy vulnerability scans on this library, there are 6 CVEs showing up that are all associated with the version of express and/or it's dependencies.

Updating to express 4.21.1 would update all of the affected libraries to versions in which the vulnerabilities have been fixed

The table below shows the affected libraries, the fixed version according to the CVE and which version of the dependent libraries are in the specified version of express

CVE Package Installed Version Fixed In express 4.20.0 express 4.21.0 express 4.21.1
CVE-2024-43796 express 4.19.2 4.20.0 4.20.0 4.21.0 4.21.1
CVE-2024-45296 path-to-regexp 0.1.7 0.1.10 or 8.0.0 0.1.10 0.1.10 0.1.10
CVE-2024-45590 body-parser 1.20.2 1.20.3 1.20.3 1.20.3 1.20.3
CVE-2024-43799 send 0.18.0 0.19.0 0.19.0 0.19.0 0.19.0
CVE-2024-43800 serve-static 1.16.0 1.16.0 1.16.0 1.16.2 1.16.2
CVE-2024-47764 cookie 0.6.0 0.7.0 0.6.0 0.6.0 0.7.1
@acalcutt
Copy link
Collaborator

acalcutt commented Nov 9, 2024

Seems like a failed test stopped that from getting updated in #1401 . If someone wants to look into that we can move it forward

@acalcutt
Copy link
Collaborator

acalcutt commented Jan 6, 2025

If you have a chance could you evaluate this PR to upgrade express to v5 and let me know if it has any issues for you
#1429

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Development

No branches or pull requests

2 participants