chore(deps): update dependency socket.io-parser to v4.2.3 [security] #30833
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
4.0.5
->4.2.3
GitHub Vulnerability Alerts
CVE-2023-32695
Impact
A specially crafted Socket.IO packet can trigger an uncaught exception on the Socket.IO server, thus killing the Node.js process.
Patches
A fix has been released today (2023/05/22):
[email protected]
[email protected]
Another fix has been released for the
3.3.x
branch:socket.io
versionsocket.io-parser
version4.5.2...latest
~4.2.0
(ref)npm audit fix
should be sufficient4.1.3...4.5.1
~4.1.1
(ref)[email protected]
3.0.5...4.1.2
~4.0.3
(ref)[email protected]
3.0.0...3.0.4
~4.0.1
(ref)[email protected]
2.3.0...2.5.0
~3.4.0
(ref)npm audit fix
should be sufficientWorkarounds
There is no known workaround except upgrading to a safe version.
For more information
If you have any questions or comments about this advisory:
Thanks to @rafax00 for the responsible disclosure.
Release Notes
Automattic/socket.io-parser (socket.io-parser)
v4.2.3
Compare Source
A malicious client could send a specially crafted HTTP request, triggering an uncaught exception and killing the Node.js process:
Please upgrade as soon as possible.
Bug Fixes
Links
v4.2.2
Compare Source
Bug Fixes
Links
v4.2.1
Compare Source
Bug Fixes
Links
v4.2.0
Compare Source
Features
Links
v4.1.2
Compare Source
Bug Fixes
Links
v4.1.1
Compare Source
Links
v4.1.0
Compare Source
Features
Links
Configuration
📅 Schedule: Branch creation - "" in timezone America/New_York, Automerge - At any time (no schedule defined).
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.