tileserver-gl icon indicating copy to clipboard operation
tileserver-gl copied to clipboard

Update to use latest mbtiles for sqlite3 vulnerability

Open ayohrling opened this issue 2 years ago • 0 comments

There is a NIST bulletin for a vulnerability in the nodejs-sqlite3 module that is used. https://nvd.nist.gov/vuln/detail/CVE-2022-21227

This is resolved in version >=5.0.2; however, the current release (3.1.1) of tileserver-gl uses @mapbox/mbtiles version 0.11.0 which is coded to 4.x module dependency for sqlite3. There was a later release of mbtiles almost 2 years ago even, 0.12.1 that utilizes ^5.0.0 which allows for easy update of the sqlite3 module to a fixed version.

ayohrling avatar Jun 15 '22 14:06 ayohrling