Skip to content

v3.32.5

Latest

Choose a tag to compare

@nthmost-orkes nthmost-orkes released this 25 Sep 04:58

v3.32.5

A security roll-up: hardens request-driven regexes against ReDoS, closes a path-traversal hole in the default payload storage, and clears outstanding CVE/CodeQL alerts in the UI.

What's Changed

  • fix(core): prevent path traversal in DummyPayloadStorage (#1651) — the default payload storage (used whenever no external S3/GCS storage is configured, so reachable in dev and default deployments) resolved caller-supplied paths against payloadDir with no validation in both upload() and download(), letting a ../-style path read or write outside the payload directory. Paths now route through a validateAndResolvePath() that normalizes, rejects residual .., and verifies the canonical path stays within payloadDir — mirroring the earlier MockExternalPayloadStorage fix (#723). Thanks @Denimworld12.
  • fix(security): replace the backtracking ${...} regex in ParametersUtils with a linear scanner (#1654) — the pattern that finds ${...} expressions is applied to every string task parameter, including output returned by workers, and its match time grew polynomially with nesting depth (a ~3 KB string of ${${...}} nested 1000 deep took over 30 seconds). Expressions are now located in a single brace-depth pass with identical semantics — $${ escaping, nested expressions, and an unclosed expression swallowing the rest of the string all behave as before. Thanks @Naman-Gururani. (Fixes #1638)
  • fix(security): hoist Pattern and prevent ReDoS in the index query builders (#1648) — PostgresIndexQueryBuilder and SqliteIndexQueryBuilder compiled their parsing regex per call and used a pattern that could catastrophically backtrack on long all-letter search input. The pattern is now compiled once and hardened so malformed queries fail fast instead of hanging the search path. Thanks @jhaabhijeet864. (Fixes #1640)
  • fix(ui): resolve ws to CVE-2024-37890 patched versions (#1672) — pins the transitive ws dev-dependency up via yarn resolutions (jsdom/ws → 7.5.13, webpack-dev-server/ws → 8.21.3), clearing the CVE alert. Thanks @nthmost. (Fixes #643)
  • fix(security): remove no-op identity replacement in the errorInspector path helper (#1660) — drops a .replace(/\]\[/g, "][") that replaced ][ with itself (a CodeQL js/identity-replacement alert); adjacent brackets like [0][1] are valid lodash nested-access syntax and were always passed through unchanged. Thanks @nthmost. (Fixes #1642)

Full Changelog: v3.32.4...v3.32.5