nteract / ion

A React-backed UI Toolkit
BSD 3-Clause "New" or "Revised" License
12 stars 5 forks source link

Update dependency react-dom to v16.4.2 [SECURITY] #59

Open renovate[bot] opened 5 years ago

renovate[bot] commented 5 years ago

This PR contains the following updates:

Package Type Update Change
react-dom (source) dependencies patch 16.4.1 -> 16.4.2

GitHub Vulnerability Alerts

CVE-2018-6341

Affected versions of react-dom are vulnerable to Cross-Site Scripting (XSS). The package fails to validate attribute names in HTML tags which may lead to Cross-Site Scripting in specific scenarios. This may allow attackers to execute arbitrary JavaScript in the victim's browser. To be affected by this vulnerability, the application needs to:

Recommendation

If you are using react-dom 16.0.x, upgrade to 16.0.1 or later.
If you are using react-dom 16.1.x, upgrade to 16.1.2 or later.
If you are using react-dom 16.2.x, upgrade to 16.2.1 or later.
If you are using react-dom 16.3.x, upgrade to 16.3.3 or later.
If you are using react-dom 16.4.x, upgrade to 16.4.2 or later.


Release Notes

facebook/react ### [`v16.4.2`](https://togithub.com/facebook/react/blob/master/CHANGELOG.md#​1642-August-1-2018) [Compare Source](https://togithub.com/facebook/react/compare/v16.4.1...v16.4.2) ##### React DOM Server - Fix a [potential XSS vulnerability when the attacker controls an attribute name](https://reactjs.org/blog/2018/08/01/react-v-16-4-2.html) (`CVE-2018-6341`). This fix is available in the latest `react-dom@16.4.2`, as well as in previous affected minor versions: `react-dom@16.0.1`, `react-dom@16.1.2`, `react-dom@16.2.1`, and `react-dom@16.3.3`. ([@​gaearon](https://togithub.com/gaearon) in [#​13302](https://togithub.com/facebook/react/pull/13302)) - Fix a crash in the server renderer when an attribute is called `hasOwnProperty`. This fix is only available in `react-dom@16.4.2`. ([@​gaearon](https://togithub.com/gaearon) in [#​13303](https://togithub.com/facebook/react/pull/13303))

Renovate configuration

:date: Schedule: "" (UTC).

:vertical_traffic_light: Automerge: Disabled by config. Please merge this manually once you are satisfied.

:recycle: Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

:no_bell: Ignore: Close this PR and you won't be reminded about this update again.



This PR has been generated by WhiteSource Renovate. View repository job log here.