Repository navigation
Nodejs using vulnerable package for ip #51848
Description
Activity
- addednpmIssues and PRs related to the npm client dependency or the npm registry.Issues and PRs related to the npm client dependency or the npm registry.
on Feb 23, 2024 If you use
npm ls -g ipyou can pinpoint exactly what depends on it, in this casenpmdepends onmake-fetch-happenwhich in turn depends on@npmcli/agentwhich depends onsocks-proxy-agent.socks-proxy-agentdepends onsocksbutsocksremoved theippackage in JoshGlazebrook/socks@66b7f73, so to fix this thesocksversion must be bumped here insocks-proxy-agentand release an update, then@npmcli/agentmust update to the new version ofsocks-proxy-agentand release an update, and thenmake-fetch-happenmust update to the new version of@npmcli/agentand release an update, and finallynpmmust update to the new version ofmake-fetch-happen... 😅Reacted by PierreDemailly, Marco Ippolito, Naineel Soyantar, Hugo Fernandes and Soujanya VithanalaYes agree with you its a very long chain. Lets see what we can do as it should be fixed.
Or, it seems npm CLI is only using
make-fetch-happenhere: https://github.com/npm/cli/blob/95b505738a73ba740227a41b8c7c87013af5acaf/lib/commands/doctor.js#L197 which can be replaced with the globalfetchsince Node.js v18...Discussion on this issue in npm repo - npm/cli#7216
Reacted by Agustin Forero and Richard CoxI think we should move this to https://github.com/nodejs/nodejs-dependency-vuln-assessments. Any concerns with moving it there?
Reacted by Joyee CheungThis is causing some issues with our security scanner. We might need to delete the dependency as part of the build process until it's fixed in the base images.
using base image
node:18-alpine- linked a pull request that will close this issuedeps: upgrade npm to 10.5.0 #51913
on Feb 28, 2024 This is causing some issues with our security scanner. We might need to delete the dependency as part of the build process until it's fixed in the base images.
using base image
node:18-alpineHow did you manage to remove it?
when do we have a fix on Node version 20 ? ip is still referencing 2.0.0
Reacted by Felix Weller, Dmitrij Kuba, Leo Cao, Pieter Develtere, Michael Fisher, Daniel and Deniz Acay
Version
v21.6.2
Platform
Linux 3aa06663b056 6.6.12-linuxkit #1 SMP PREEMPT_DYNAMIC Tue Jan 30 09:48:40 UTC 2024 x86_64 Linux
Subsystem
ip
What steps will reproduce the bug?
Build container image with node version v21.6.2 and scan it using any image scanning tool available.
It will report the medium severity vulnerability in ip package which is bundled as deps for nodejs here: https://github.com/nodejs/node/blob/main/deps/npm/node_modules/ip/package.json
You can also find the more information about this vulnerability here: GHSA-78xj-cgh5-2h22
How often does it reproduce? Is there a required condition?
No response
What is the expected behavior? Why is that the expected behavior?
You should change the ip package version to 2.0.1.
What do you see instead?
Medium Severity Vulnerability
Additional information
No response