dpa99c / cordova-custom-config

Cordova/Phonegap plugin to update platform configuration files based on preferences and config-file data defined in config.xml
318 stars 84 forks source link

Snyk report: High severity vulnerability found in plist -> Regular Expression DOS #155

Closed gabriele-sacchi closed 5 years ago

gabriele-sacchi commented 5 years ago

Bug Report

Problem

Snyk (https://www.npmjs.com/package/snyk) querying a database of known vulnerabilities revealed this critical security vulnerability:

✗ High severity vulnerability found in plist
  Description: Regular Expression Denial of Service (ReDoS)
  Info: https://snyk.io/vuln/npm:plist:20180219
  Introduced through: cordova-custom-config@5.0.3
  From: cordova-custom-config@5.0.3 > xcode@1.1.0 > simple-plist@0.2.1 > plist@2.0.1

What is expected to happen?

No security vulnerabilities should be found by Snyk

What does actually happen?

High severity security vulnerability found by Snyk

Information

Steps to reproduce:

Command or Code

See above

Environment, Platform, Device

Any

Version information

latest

Checklist

dpa99c commented 5 years ago

See https://github.com/dpa99c/cordova-custom-config/issues/154#issuecomment-475516096