Skip to content

Commit fc29778

Browse files
committed
chore(release notes): add two more CVEs which are fixed in 1.3.1 but which we forgot to uncomment
Signed-off-by: Nick Boldt <[email protected]>
1 parent 362e043 commit fc29778

File tree

2 files changed

+8
-4
lines changed

2 files changed

+8
-4
lines changed
Lines changed: 2 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,4 @@
11
# CVE number, affected package, fixed in version(s), JIRA
2+
CVE-2024-21536,http-proxy-middleware,2.0.7||3.0.3,RHIDP-4612
3+
CVE-2024-37890,ws,8.17.1||7.5.10||6.2.3||5.2.4,RHIDP-2733
24
CVE-2024-45590,body-parser,1.20.3,RHIDP-3917,mostly fixed but missed immobiliarelabs-backstage-plugin-gitlab-backend-dynamic
3-
4-
# not yet fixed, built, or ready for release
5-
# CVE-2024-37890,ws,8.17.1||7.5.10||6.2.3||5.2.4,RHIDP-2733
6-
# CVE-2024-21536,http-proxy-middleware,2.0.7||3.0.3,RHIDP-4612
Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,10 @@
11
= {product} dependency updates
22

3+
link:https://access.redhat.com/security/cve/CVE-2024-21536[CVE-2024-21536]::
4+
A flaw was found in the http-proxy-middleware package. Affected versions of this package are vulnerable to denial of service (DoS) due to an UnhandledPromiseRejection error thrown by micromatch. This flaw allows an attacker to kill the Node.js process and crash the server by requesting certain paths.
5+
6+
link:https://access.redhat.com/security/cve/CVE-2024-37890[CVE-2024-37890]::
7+
A flaw was found in the Node.js WebSocket library (ws). A request with several headers exceeding the 'server.maxHeadersCount' threshold could be used to crash a ws server, leading to a denial of service.
8+
39
link:https://access.redhat.com/security/cve/CVE-2024-45590[CVE-2024-45590]::
410
A flaw was found in body-parser. This vulnerability causes denial of service via a specially crafted payload when the URL encoding is enabled.

0 commit comments

Comments
 (0)