Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

win-ca dependent library has security vulnerability #42

Open
BHANU2705 opened this issue Jan 12, 2022 · 4 comments
Open

win-ca dependent library has security vulnerability #42

BHANU2705 opened this issue Jan 12, 2022 · 4 comments

Comments

@BHANU2705
Copy link

BHANU2705 commented Jan 12, 2022

The node-forge-0.10.0.tgz has a security vulnerability.

CVE-2022-0122
JavaScript implementations of network transports, cryptography, ciphers, PKI, message digests, and various utilities.

The latest available version of node-forge is 1.2.1.

Please upgrade the version of node-forge and release an updated version of win-ca.

@stein321
Copy link

I opened this PR, but looks like some tests are failing due to it or flaky tests: #43

@WilliamRADFunk
Copy link

Any chance we can up the priority on this PR getting in? win-ca is the only dependency we have left that still uses the vulnerable version of node-forge.

@stein321
Copy link

this is resolved @BHANU2705

@gjsjohnmurray
Copy link

@ukoloff I think this can be closed, right?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants