Webpack-dev-server: A vulnerability found in webpack-dev-server

Created on 24 Jul 2018  路  9Comments  路  Source: webpack/webpack-dev-server

Hi, I found a vulnerability in webpack-dev-server, how do I report it to you?

1 (critical) ws(s) 1 (security) bug

Most helpful comment

In webpack-dev-server 2.11.3, npm audit found 1 high severity vulnerability.
+1 @xhocquet . We need a 2.x security update patch.

All 9 comments

@chromium1337 It is problem in dependencies or in webpack-dev-server code?

@evilebottnawi It's in webpack-dev-server code, not dependencies.

@chromium1337 please send details to sheo13666q @ gmail . com

Hi,
Not sure if it's the same vulnerability. I was just warn by NPM about these vulnerabilities which webpack-dev-server depends on:
vulnerabilities

馃憢 Hi I am looking at this issue as it seems to relate to these security advisories:

As far as I can tell, the fix commit has not made it to master nor been released? Both the NPM Advisory and CVE report a fix version of 3.1.6, but nothing in 3.1.6 release looks like the fix for this? The bugfix/origin-header branch needs a PR and to get merged and deployed.

Am I mistaken or has the fix for this not really been deployed?

This package is widely used so I am looking at this from the perspective of making sure the public data sources are correct.

CC fix commit author @sokra

this package should be used only for development purpose, so it is not very high priority

@evilebottnawi Could you please advise the state of this vulnerability in webpack-dev-server 2.11.3? Is this vulnerability present, and if so is there a possibility of adding this patch as a security update?

In webpack-dev-server 2.11.3, npm audit found 1 high severity vulnerability.
+1 @xhocquet . We need a 2.x security update patch.

Was this page helpful?
0 / 5 - 0 ratings

Related issues

mischkl picture mischkl  路  3Comments

antoinerousseau picture antoinerousseau  路  3Comments

uMaxmaxmaximus picture uMaxmaxmaximus  路  3Comments

nikirossi picture nikirossi  路  3Comments

tulika21-zz picture tulika21-zz  路  3Comments