Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

CVE-2022-0122 - Update xml-encryption (fixed in 3.x, pending for 4.x) #666

Closed
alexross1988 opened this issue Jan 19, 2022 · 6 comments
Closed
Labels

Comments

@alexross1988
Copy link

In the latest 3.2.0, xml-encryption is currently using a version of node-forge with a CVE.
Bumping to 2.0.0 here https://github.com/node-saml/passport-saml/blob/v3.2.0/package.json#L57 would solve this following the work they've done under auth0/node-xml-encryption#94

CVE-2022-0122 (severity: High)

forge is vulnerable to URL Redirection to Untrusted Site

@forty
Copy link
Contributor

forty commented Jan 19, 2022

There it is #667 (this is for branch 3.x, I'll do the same on master later if no one else does it before)

@markstos
Copy link
Contributor

@forty Patching the master branch as well would be great, thanks.

@kemarsh
Copy link

kemarsh commented Jan 20, 2022

Thanks for the quick response - is there an ETA for when the updated 3.2.X version will be published to NPM?

@markstos
Copy link
Contributor

I started working on this today, but ran into some speed bumps and am out of time for the moment. As logged in #668, I ran into an test failure. But that's not a blocker now that I've confirmed I get the same test failure before the change was made on 3.2.0.

Also, although I'm not sure if there are publicly visible, there are 4 or 5 other "dependabot alerts" for other dependencies that could use an update. So as long as we are doing a security-focused release, I'll check that we are up-to-date with other deps as well. Perhaps later tonight or tomorrow.

@markstos
Copy link
Contributor

3.2.1 has been released.

@cjbarth I presume the commits here need to be ported to the 4.x branch.

@markstos markstos changed the title CVE-2022-0122 - Update xml-encryption CVE-2022-0122 - Update xml-encryption (fixed in 3.x, pending for 4.x) Feb 2, 2022
@cjbarth
Copy link
Collaborator

cjbarth commented Apr 4, 2022

This has been patched on master via #685

@cjbarth cjbarth closed this as completed Apr 4, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

5 participants