facebook-nodejs-business-sdk icon indicating copy to clipboard operation
facebook-nodejs-business-sdk copied to clipboard

Prototype Pollution vulenrability

Open andrew-itscript opened this issue 4 years ago • 7 comments

Which SDK version are you using?

^12.0.1

What's the issue?

Snyk reporting Prototype Pollution vulenrability

Steps/Sample code to reproduce the issue

https://app.snyk.io/test/npm/facebook-nodejs-business-sdk/12.0.1

Observed Results:

snyk_issue

Expected Results:

No vulnerabilities should be found by Snyk

andrew-itscript avatar Apr 08 '21 04:04 andrew-itscript

Hey there, it looks like there has been no activity on this issue recently. Has the issue been fixed, or does it still require the community's attention? This issue may be closed if no further activity occurs. Thank you for your contributions.

stale[bot] avatar Jan 09 '22 02:01 stale[bot]

it still requires the community's attention. Prototype Pollution vulenrability is not fixed. Please see

Prototype Pollution [High Severity][https://snyk.io/vuln/SNYK-JS-MOUT-1014544] in [email protected]
introduced by [email protected] > [email protected] > [email protected]

andrew-itscript avatar Jan 10 '22 11:01 andrew-itscript

Still an issue

JollyTeo avatar Feb 11 '22 15:02 JollyTeo

https://github.com/advisories/GHSA-pc58-wgmc-hfjr for more info. Still an issue.

jfaylon avatar Feb 25 '22 18:02 jfaylon

Still an issue:

# npm audit report

mout  <1.2.3
Severity: high
Prototype Pollution in mout - https://github.com/advisories/GHSA-pc58-wgmc-hfjr
fix available via `npm audit fix --force`
Will install [email protected], which is a breaking change
node_modules/mout
  iso-3166-1-alpha-2  *
  Depends on vulnerable versions of mout
  node_modules/iso-3166-1-alpha-2
    facebook-nodejs-business-sdk  >=6.0.1
    Depends on vulnerable versions of iso-3166-1-alpha-2
    node_modules/facebook-nodejs-business-sdk

remarkablemark avatar Mar 07 '22 17:03 remarkablemark

Is it possible to prioritize fixing of this vulnerability as it impacts negatively on cybersecurity report and business?

andrew-ignatiev avatar Mar 23 '22 04:03 andrew-ignatiev

Any updates? image

StephaneBischoff avatar May 04 '22 20:05 StephaneBischoff

@facebook-github-bot why the issue is closed when PR merge was failed ? Could you drop support of Node.js version 8?

andrew-ignatiev avatar Nov 29 '22 07:11 andrew-ignatiev

npm's automated fix seems to cause a rollback to version 6.0.0

It would be great to remove this, please!

Dezzymei avatar Dec 19 '22 18:12 Dezzymei