polonel / trudesk

:coffee: :seedling: Trudesk is an open-source help desk/ticketing solution.
http://trudesk.io
Other
1.29k stars 430 forks source link

Multiple vulnerabilities found #631

Closed nunodsfernandes closed 1 year ago

nunodsfernandes commented 1 year ago

Is this a BUG REPORT or FEATURE REQUEST?:

What happened: Scans found multiple vulnerabilities on a vanilla Trudesk install.

Packages:

[REDACTED]

GH Reference [REDACTED]

What did you expect to happen: Any mitigation for these issues?

How to reproduce it (as minimally and precisely as possible): This was the result of a scan conducted by an external tool (Wiz Scan).

Anything else we need to know?:

Environment:

polonel commented 1 year ago

We utilize Synk for vulnerability patching/testing. There is already an active PR for Mongoose and the others are unverified.

Please email security vulnerabilities directly or report them on https://huntr.dev to prevent exposure before a patch is available from the third-party maintainer.

Thus I am deleting this issue and encourage you to report them to my email or https://huntr.dev