Skip to content
This repository has been archived by the owner on Nov 20, 2023. It is now read-only.

fix(deps): update dependency class-validator to ^0.14.0 [security] #30

Open
wants to merge 1 commit into
base: main
Choose a base branch
from

Conversation

deepcrawltech
Copy link

@deepcrawltech deepcrawltech commented Jan 11, 2023

This PR contains the following updates:

Package Type Update Change
class-validator dependencies minor ^0.13.2 -> ^0.14.0

GitHub Vulnerability Alerts

CVE-2019-18413

In TypeStack class-validator, validate() input validation can be bypassed because certain internal attributes can be overwritten via a conflicting name. Even though there is an optional forbidUnknownValues parameter that can be used to reduce the risk of this bypass, this option is not documented and thus most developers configure input validation in the vulnerable default manner. With this vulnerability, attackers can launch SQL Injection or XSS attacks by injecting arbitrary malicious input.

The default settings for forbidUnknownValues has been changed to true in 0.14.0.

NOTE: a software maintainer agrees with the "is not documented" finding but suggests that much of the responsibility for the risk lies in a different product.


Release Notes

typestack/class-validator (class-validator)

v0.14.0

Compare Source


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

@deepcrawltech deepcrawltech changed the title fix(deps): update dependency class-validator to ^0.14.0 [security] fix(deps): update dependency class-validator to ^0.14.0 [security] - autoclosed Mar 7, 2023
@deepcrawltech deepcrawltech deleted the renovate/npm-class-validator-vulnerability branch March 7, 2023 01:02
@deepcrawltech deepcrawltech changed the title fix(deps): update dependency class-validator to ^0.14.0 [security] - autoclosed fix(deps): update dependency class-validator to ^0.14.0 [security] Mar 7, 2023
@deepcrawltech deepcrawltech reopened this Mar 7, 2023
@deepcrawltech deepcrawltech changed the title fix(deps): update dependency class-validator to ^0.14.0 [security] fix(deps): update dependency class-validator to ^0.14.0 [security] - autoclosed Mar 13, 2023
@deepcrawltech deepcrawltech changed the title fix(deps): update dependency class-validator to ^0.14.0 [security] - autoclosed fix(deps): update dependency class-validator to ^0.14.0 [security] Mar 13, 2023
@deepcrawltech deepcrawltech reopened this Mar 13, 2023
@deepcrawltech deepcrawltech restored the renovate/npm-class-validator-vulnerability branch March 13, 2023 16:05
@deepcrawltech deepcrawltech changed the title fix(deps): update dependency class-validator to ^0.14.0 [security] fix(deps): update dependency class-validator to ^0.14.0 [security] - autoclosed Mar 14, 2023
@deepcrawltech deepcrawltech deleted the renovate/npm-class-validator-vulnerability branch March 14, 2023 21:05
@deepcrawltech deepcrawltech changed the title fix(deps): update dependency class-validator to ^0.14.0 [security] - autoclosed fix(deps): update dependency class-validator to ^0.14.0 [security] Mar 14, 2023
@deepcrawltech deepcrawltech reopened this Mar 14, 2023
@deepcrawltech deepcrawltech restored the renovate/npm-class-validator-vulnerability branch March 14, 2023 22:02
@deepcrawltech deepcrawltech changed the title fix(deps): update dependency class-validator to ^0.14.0 [security] fix(deps): update dependency class-validator to ^0.14.0 [security] - autoclosed Apr 18, 2023
@deepcrawltech deepcrawltech deleted the renovate/npm-class-validator-vulnerability branch April 18, 2023 19:02
@deepcrawltech deepcrawltech changed the title fix(deps): update dependency class-validator to ^0.14.0 [security] - autoclosed fix(deps): update dependency class-validator to ^0.14.0 [security] Apr 18, 2023
@deepcrawltech deepcrawltech reopened this Apr 18, 2023
@deepcrawltech deepcrawltech restored the renovate/npm-class-validator-vulnerability branch April 18, 2023 20:02
@deepcrawltech deepcrawltech changed the title fix(deps): update dependency class-validator to ^0.14.0 [security] fix(deps): update dependency class-validator to ^0.14.0 [security] - autoclosed May 4, 2023
@deepcrawltech deepcrawltech deleted the renovate/npm-class-validator-vulnerability branch May 4, 2023 18:03
@deepcrawltech deepcrawltech changed the title fix(deps): update dependency class-validator to ^0.14.0 [security] - autoclosed fix(deps): update dependency class-validator to ^0.14.0 [security] May 4, 2023
@deepcrawltech deepcrawltech reopened this May 4, 2023
@deepcrawltech deepcrawltech restored the renovate/npm-class-validator-vulnerability branch May 4, 2023 19:02
@deepcrawltech deepcrawltech changed the title fix(deps): update dependency class-validator to ^0.14.0 [security] fix(deps): update dependency class-validator to ^0.14.0 [security] - autoclosed May 25, 2023
@deepcrawltech deepcrawltech deleted the renovate/npm-class-validator-vulnerability branch May 25, 2023 07:05
@deepcrawltech deepcrawltech changed the title fix(deps): update dependency class-validator to ^0.14.0 [security] - autoclosed fix(deps): update dependency class-validator to ^0.14.0 [security] May 25, 2023
@deepcrawltech deepcrawltech reopened this May 25, 2023
@deepcrawltech deepcrawltech restored the renovate/npm-class-validator-vulnerability branch May 25, 2023 08:04
@deepcrawltech deepcrawltech changed the title fix(deps): update dependency class-validator to ^0.14.0 [security] fix(deps): update dependency class-validator to ^0.14.0 [security] - autoclosed Jun 12, 2023
@deepcrawltech deepcrawltech deleted the renovate/npm-class-validator-vulnerability branch June 12, 2023 16:01
@deepcrawltech deepcrawltech changed the title fix(deps): update dependency class-validator to ^0.14.0 [security] - autoclosed fix(deps): update dependency class-validator to ^0.14.0 [security] Jun 12, 2023
@deepcrawltech deepcrawltech reopened this Jun 12, 2023
@deepcrawltech deepcrawltech restored the renovate/npm-class-validator-vulnerability branch June 12, 2023 17:03
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants