Create-react-app: Security: Bump terser-webpack-plugin to address CVE-2020-7660

Created on 4 Jun 2020  路  11Comments  路  Source: facebook/create-react-app

The Problem

react-scripts-3.4.1 relies on terser-webpack-plugin-2.3.5 which then relies on serialize-javascript-2.1.2, which is vulnerable per https://nvd.nist.gov/vuln/detail/CVE-2020-7660.

My Ask

Can terser-webpack-plugin be bumped to 2.3.7, which relies on serialize-javascript ^3.1.0? This would address this vulnerability.

This is similar to #8159.

bug report needs triage

Most helpful comment

IMO it's still valid and a new release would be much appreciated :)

All 11 comments

They've already fixed it in the master (https://github.com/facebook/create-react-app/pull/8950/files) so I guess we should wait for the next release?

Good catch, yeah, looks like next release should get us there.

Does anyone know when the next release happens?

Do we know when this release will be coming? Just to be prepared for when to upgrade 馃槃

This issue has been automatically marked as stale because it has not had any recent activity. It will be closed in 5 days if no further activity occurs.

IMO it's still valid and a new release would be much appreciated :)

This issue has been automatically marked as stale because it has not had any recent activity. It will be closed in 5 days if no further activity occurs.

Bump - this is still an issue and there still has not been any new release.

@AjkayAlan - Not sure if this is helpful or not for you but raised this discussion for confirmation of releases as I have noticed their have been newer releases but also I am aware CRA 4 is also in progress so wanted to find out if these fixes are safe to use now
https://github.com/facebook/create-react-app/discussions/9484

@AjkayAlan - I managed to get an answer here in #9484 about the new versions and getting this fix released

https://github.com/facebook/create-react-app/discussions/9484#discussioncomment-52089

Thanks @olliecurtis! Based on the new release existing in npmjs, I think it solves our issue.

Closing.

Was this page helpful?
0 / 5 - 0 ratings

Related issues

wereHamster picture wereHamster  路  3Comments

barcher picture barcher  路  3Comments

xgqfrms-GitHub picture xgqfrms-GitHub  路  3Comments

adrice727 picture adrice727  路  3Comments

stopachka picture stopachka  路  3Comments