in2code-de / luxletter

Newsletter system for TYPO3
https://www.in2code.de/agentur/typo3-extensions/luxletter/
23 stars 25 forks source link

Known vulnerabilities in 3rd-party dependency chart.js #171

Closed magicHatOfTYPO3 closed 1 year ago

magicHatOfTYPO3 commented 1 year ago

Hi. We have received a PenTest result which complains about using a vulnerable version of charts.js as dependency from luxletter.

As far I can see the chart.js from Luxletter is vulnerable against a Prototype Pollution Attack, see https://security.snyk.io/package/npm/chart.js/2.7.1

Is there any chance to use a current version of chart.js or at least a minor update to a version with no known security issues?

Or: is it possible to deactivate the chart.js support completely (with then no charts in the backend, of course)?

einpraegsam commented 1 year ago

Merged. Will be release asap.

magicHatOfTYPO3 commented 1 year ago

Thanks a lot :)