Akkadius / glass-isc-dhcp

Glass - ISC DHCP Server Interface
MIT License
684 stars 142 forks source link

Please archive / freeze this project #94

Closed mrgohin closed 8 months ago

mrgohin commented 2 years ago

Hello,

I tried to use your software today. Unfortunately this is impossible without massive security concerns.

After npm install I had already seen everything: 34 vulnerabilities (7 low, 9 moderate, 12 high, 6 critical)

I'm totally fine with this (expected) result since the project didn't received any update since release. But I'd recommend to archive it so everybody can notice it at first sight.

I also would be interessted to see what this software is capabale of. Maybe one day there is an update coming ;-)

zedaprime commented 2 years ago

Hi m4k5ym,

Thanks for your initiative. I suspect this author can run that and other freely available scanning tools. It often takes research to see if the flagged vulnerability is applicable. Also noticing the recommended firewall rules mitigate many concerns.

Please feel free to post code patches for any that you are able to identify specifically with a resolution. This is community software, please feel free to chip in.

madtempest commented 2 years ago

Theres a number of forks that have updated libraries and done fixes where broken. Perhaps try one of those instead?

mrgohin commented 2 years ago

I would recommend using kea-dhcp with stork management. Its the official successor of isc-dhcp-server with a lot of enhancement

piozylka commented 9 months ago

AFAIK kea stork doesn't allow to modify files with dhcp reservation without paying for enterprise edition. with glass-isc-dhcp it's free

mrgohin commented 8 months ago

Yeah it might be free. The vulnerabilities you get as a goodie are as well for free.

Have fun with a product of the broken npm eco system. By design.