Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Critical crypto-js vulnerability (CVE-2023-46233) #165

Open
mauricewegner opened this issue Oct 26, 2023 · 4 comments
Open

Critical crypto-js vulnerability (CVE-2023-46233) #165

mauricewegner opened this issue Oct 26, 2023 · 4 comments

Comments

@mauricewegner
Copy link

CVE-2023-46233 (cve.org)

Affected versions < 4.2.0
It would be great if you could bump it.

@rameshvr
Copy link

Crypto-js is no longer maintained. we should update code to use native crypto
https://www.npmjs.com/package/crypto-js

@mauricewegner
Copy link
Author

Fixed via #168

@mauricewegner
Copy link
Author

mauricewegner commented Dec 12, 2023

The release of 3.19.0 re-introduces this vulnerability as it downgraded the crypto-js library again (1e5ae78)

A new release with #170 included would resolve this issue.

@mauricewegner mauricewegner reopened this Dec 12, 2023
@SteveOfficerSeccl
Copy link
Contributor

FYI PR #174 just re-introduced crypto-js

This was referenced Jan 18, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants