Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

plist update to version 3.0.6 needed #26089

Closed
schuetza opened this issue Mar 13, 2023 · 0 comments · Fixed by #26631
Closed

plist update to version 3.0.6 needed #26089

schuetza opened this issue Mar 13, 2023 · 0 comments · Fixed by #26631
Labels
E2E Issue related to end-to-end testing good first issue Good for newcomers Triaged Issue has been routed to backlog. This is not a commitment to have it prioritized by the team. type: security 🔐 Security related

Comments

@schuetza
Copy link

Current behavior

plist had a CVE in recent version, but the reporting in the relevant databases seems to be incorrect.
NVD and CVE list only version 3.0.4 and 3.0.5 to be affected, (https://nvd.nist.gov/vuln/detail/CVE-2022-22912#range-8131646) but according to the comments in the owners git repository the fix for CVE-2022-26260 didn't make it into plist:3.0.5, which is currently packaged with cypress.

plist should be updated to v.3.0.6

see TooTallNate/plist.js#128 and TooTallNate/plist.js#114

Desired behavior

No response

Test code to reproduce

Scan the zip package, e.g. using scanner provided at https://github.com/jeremylong/DependencyCheck

Location:
Cypress/resources/app/packages/launcher/package.json?launcher:0.0.0-development/plist:3.0.5

Cypress Version

12.7

Node version

18

Operating System

Linux

Debug Logs

No response

Other

No response

@nagash77 nagash77 added type: security 🔐 Security related routed-to-e2e E2E Issue related to end-to-end testing labels Mar 13, 2023
@nagash77 nagash77 added Triaged Issue has been routed to backlog. This is not a commitment to have it prioritized by the team. and removed routed-to-e2e labels Apr 19, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
E2E Issue related to end-to-end testing good first issue Good for newcomers Triaged Issue has been routed to backlog. This is not a commitment to have it prioritized by the team. type: security 🔐 Security related
Projects
None yet
Development

Successfully merging a pull request may close this issue.

3 participants