botbuilder-js icon indicating copy to clipboard operation
botbuilder-js copied to clipboard

Dependency `loadsh.trimend` is out of date and the dependency has known public CVEs - CVE-2020-28500

Open leen1218 opened this issue 1 year ago • 13 comments

loadsh.trimend package is transitive dependency of botbuilder and botbuilder-dialogs.

botbuilder-dialogs --> @microsoft/recognizers-text-suite --> @microsoft/recognizers-text-number --> lodash.trimend

But for loadsh.trimend package https://www.npmjs.com/package/lodash.trimend, version 4.5.1 is already the latest version 8 years ago and seems loadsh.trimend is not maintained any more.

leen1218 avatar Nov 20 '24 03:11 leen1218

It looks like there was a previous issue where this was potentially fixed but it was not. https://github.com/microsoft/botbuilder-js/issues/4579 Additionally here is a closed issue from lodash https://github.com/lodash/lodash/issues/5643

cbelsole avatar Nov 21 '24 16:11 cbelsole

@ceciliaavila Any update on this?

cbelsole avatar Nov 25 '24 14:11 cbelsole

@ceciliaavila Any update on this?

Hi @cbelsole, we started working on this issue today. Version 1.3 of Recognizers-Text has this issue fixed, but we can't upgrade to that without introducing breaking changes.

ceciliaavila avatar Nov 25 '24 14:11 ceciliaavila

@ceciliaavila Any update on this?

cbelsole avatar Dec 06 '24 16:12 cbelsole

@ceciliaavila Any update on this?

Hi @cbelsole, we need to finish testing the fix we did for this. We'll keep you posted.

ceciliaavila avatar Dec 09 '24 14:12 ceciliaavila

Hi @ceciliaavila , any update on this?

leen1218 avatar Jan 17 '25 02:01 leen1218

Hi @ceciliaavila , any update on this?

Hi @leen1218, an open PR with the fix is under review.

ceciliaavila avatar Jan 17 '25 12:01 ceciliaavila

@ceciliaavila any update on the PR progress or any plan to merge the PR? Thanks.

leen1218 avatar Feb 10 '25 04:02 leen1218

@ceciliaavila Hi, any update on it? This security vulnerability has been for a couple of years.

guy-microsoft avatar May 18 '25 11:05 guy-microsoft

@ceciliaavila can you provide an update, and possibly an ETA for this? We (Microsoft) are internally affected by this. Our software is being flagged and the alternative (m365 agents sdk) is not ready for prime time for a migration yet.

XVincentX avatar Aug 04 '25 01:08 XVincentX

@ceciliaavila can you provide an update, and possibly an ETA for this? We (Microsoft) are internally affected by this. Our software is being flagged and the alternative (m365 agents sdk) is not ready for prime time for a migration yet.

Hi @tracyboehrer, there's considerable interest in the fix mentioned in #4818. Do we have any plans for a version release that includes this?

ceciliaavila avatar Aug 04 '25 13:08 ceciliaavila

@ceciliaavila ping - I am unable to get @tracyboehrer's attention through MS Teams. Maybe you'll have more luck.

XVincentX avatar Aug 18 '25 16:08 XVincentX