Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

constantinople 3.0.2 arbitrary code execution vulnerability #12

Open
tekowalsky opened this issue Apr 1, 2023 · 2 comments
Open

constantinople 3.0.2 arbitrary code execution vulnerability #12

tekowalsky opened this issue Apr 1, 2023 · 2 comments

Comments

@tekowalsky
Copy link

jade "~1.11.0" in /server/package.json is dependent on constantinople 3.0.2
jade was last update 8 years ago.
Replaced by pug

constantinople 3.0.2 has a sandbox bypass vulnerability leading to arbitrary code execution.
The earliest fixed version of constantinople is 3.1.1

https://osv.dev/vulnerability/GHSA-4vmm-mhcq-4x9j

@tekowalsky
Copy link
Author

jade also creates a dependency on critically vulnerable version 2.2.5 of uglify-js via transformers 2.1.0

@sudityashrivastav
Copy link

It means 200+ projects are vulnerable to rce

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants