Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

!!! IMPORTANT !!! = Critical Security Advisories in dependency vm2 #1680

Closed
Justman100 opened this issue Jan 1, 2024 · 6 comments
Closed

Comments

@Justman100
Copy link

Justman100 commented Jan 1, 2024

Hi, when installing the dependencies, this pokes me in the eye:

formio-workers > vm2@3.9.19: The library contains critical security issues and should not be used for production! The maintenance of the project has been discontinued. Consider migrating your code to isolated-vm.

For more details, see here and here


So, it will be recommed, to migrate vm2 code to isolated-vm

@Justman100
Copy link
Author

@lane-formio
Copy link
Contributor

lane-formio commented Jan 2, 2024

@Justman100
Thank you for your vigilance. This is a very high priority vulnerability for us and we have a development effort dedicated to resolving this as soon as possible.

Edit: Attaching our internal ticket number for anyone else that may be tracking this issue through our support channels. FIO-7167

@RachelAmbler
Copy link

Any update on this?

@brendanbond
Copy link
Contributor

Hi @RachelAmbler the next major release of our enterprise server product should have the required changes to our javascript execution contexts, we expect it very soon - thanks for your patience!

@travist
Copy link
Member

travist commented Jan 18, 2024

There are 2 pull requests to watch for this resolution.

We understand that this is a long time coming, but it did require us to refactor our server-side data processing system to make it work in a way that was performant and extensible. It is our #1 priority to resolve this issue so it is coming very soon.

@brendanbond
Copy link
Contributor

Resolved by #1693, vm2 is no longer a dependency in master and upcoming tags

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

5 participants