Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

vunerability in webpack-dev-middleware #27347

Closed
1 task
joematthews opened this issue Mar 24, 2024 · 2 comments
Closed
1 task

vunerability in webpack-dev-middleware #27347

joematthews opened this issue Mar 24, 2024 · 2 comments

Comments

@joematthews
Copy link

joematthews commented Mar 24, 2024

Command

build

Is this a regression?

  • Yes, this behavior used to work in the previous version

The previous version in which this bug was not present was

No response

Description

This is not a bug, the dependency webpack-dev-middleware for @angular-devkit/build-angular has a vulnerability.

results of npm audit on a 17.3.1 project:

# npm audit report

webpack-dev-middleware  6.0.0 - 6.1.1
Severity: high
Path traversal in webpack-dev-middleware - https://github.com/advisories/GHSA-wr3j-pwj9-hqq6
fix available via `npm audit fix --force`
Will install @angular-devkit/[email protected], which is a breaking change
node_modules/webpack-dev-middleware
  @angular-devkit/build-angular  15.1.0-next.0 - 17.3.1
  Depends on vulnerable versions of webpack-dev-middleware
  node_modules/@angular-devkit/build-angular

2 high severity vulnerabilities

Minimal Reproduction

n/a

Exception or Error

n/a

Your Environment

n/a

Anything else relevant?

Is there a tracking issue for this vulnerability within the Angular projects? What are the risks to projects built with this vulnerability?

@JoostK
Copy link
Member

JoostK commented Mar 24, 2024

Duplicate of #27334, updates will be released in the upcoming days (typically Wednesdays)

@JoostK JoostK closed this as not planned Won't fix, can't repro, duplicate, stale Mar 24, 2024
@angular-automatic-lock-bot
Copy link

This issue has been automatically locked due to inactivity.
Please file a new issue if you are encountering a similar or related problem.

Read more about our automatic conversation locking policy.

This action has been performed automatically by a bot.

@angular-automatic-lock-bot angular-automatic-lock-bot bot locked and limited conversation to collaborators Apr 24, 2024
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants