cors-proxy icon indicating copy to clipboard operation
cors-proxy copied to clipboard

Security issue in @isomorphic-git/cors-proxy

Open colin-ife-snyk opened this issue 4 years ago • 5 comments
trafficstars

Hi, 👋

A security issue in @isomorphic-git/cors-proxy was disclosed to us from an independent researcher. Please could a maintainer of this project contact me by email (via my GitHub profile) so that we can discuss the issue privately?

Kind regards, Snyk Security Team

colin-ife-snyk avatar Oct 22 '21 17:10 colin-ife-snyk

Question, did this ever get resolved?

(I'm not a maintainer of isomorphic git (yet), but I am a developer who uses i in my code.)

LeifAndersen avatar Sep 01 '22 06:09 LeifAndersen

I just realized this issue exists. I'm the current maintainer, but I think that I've become one after the issue was created. That's why I've missed this.

jcubic avatar Oct 26 '22 15:10 jcubic

Are there plans to fix and disclose the issue?

mainrs avatar Nov 07 '22 17:11 mainrs

Ask @colin-ife-snyk he didn't reply to my email.

jcubic avatar Nov 07 '22 18:11 jcubic

If he will not reply I will contact the Snyk team, maybe he doesn't work there anymore and the information on his GitHub profile are outdated. FWIW I didn't get a bounce email.

jcubic avatar Nov 07 '22 18:11 jcubic