-
|
I got strange behavior on my vps where I host diff apps. can you "maintainers" please give a statemend to this react cve I saw you updated the reace version the apps uses, but I dont see any transparent cheers |
Beta Was this translation helpful? Give feedback.
Replies: 2 comments 2 replies
-
|
Yes, Rallly is built with Next.js and so it was vulnerable to the React2Shell CVE. I updated the vulnerable dependencies the day the CVE was announced and released a patch for self-hosters with instructions to update immediately. I've gotten a number of reports now from users running vulnerable versions and it's clear that I need a better way to communicate these sorts of issues to administrators of self-hosted instances. I'm open to suggestions on how this should be communicated. |
Beta Was this translation helpful? Give feedback.
-
|
damn, well at least a yellow banner on your github page ? that indicates it clearly and transparent that If I need to read your release notes, and ask questions if its vulnerable, |
Beta Was this translation helpful? Give feedback.
Yes, Rallly is built with Next.js and so it was vulnerable to the React2Shell CVE. I updated the vulnerable dependencies the day the CVE was announced and released a patch for self-hosters with instructions to update immediately.
I've gotten a number of reports now from users running vulnerable versions and it's clear that I need a better way to communicate these sorts of issues to administrators of self-hosted instances. I'm open to suggestions on how this should be communicated.