OpenCTI-Platform / opencti

Open Cyber Threat Intelligence Platform
https://opencti.io
Other
6.41k stars 946 forks source link

Node.js vulnerabilities #8349

Closed Security-Team12 closed 1 month ago

Security-Team12 commented 2 months ago

Summary

I have OpenCTI platform V6.2.6 and i am reaching out to request an update of Node.js on our platform from version 10.19 to 10.22 in order to patch some known vulnerabilities (CVE-2020-8201,CVE-2020-8251,CVE-2020-8252) in the current version.

Could you please confirm if this update could cause any functionality issues or disruptions within our platform? We would like to ensure a smooth transition and avoid any potential conflicts.

Looking forward to your guidance and confirmation on this matter.

Thank you for your assistance.

Best regards,

richard-julien commented 2 months ago

The current docker image of the platform is using nodejs 20+ through node:20-alpine