Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

OSVDB-126747 in uglifier #2

Closed
suriyaa opened this issue Apr 9, 2016 · 1 comment
Closed

OSVDB-126747 in uglifier #2

suriyaa opened this issue Apr 9, 2016 · 1 comment
Assignees
Milestone

Comments

@suriyaa
Copy link
Contributor

suriyaa commented Apr 9, 2016

Security issue from Hakiri: The upstream library for the Ruby uglifier gem, UglifyJS, is affected by a vulnerability that allows a specially crafted Javascript file to have altered functionality after minification.

This bug, found in UglifyJS versions 2.4.23 and earlier, was demonstrated to allow potentially malicious code to be hidden within secure code, and activated by the minification process.

For more information, consult: https://zyan.scripts.mit.edu/blog/backdooring-js/

See:

@suriyaa suriyaa added this to the Hakiri milestone Apr 9, 2016
@suriyaa suriyaa self-assigned this Apr 9, 2016
@suriyaa
Copy link
Contributor Author

suriyaa commented Apr 9, 2016

✅ Fixed vulnerability in 1e45473 and a47fb9a!

@suriyaa suriyaa closed this as completed Apr 9, 2016
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant