Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Multiple vulnerabilities found #631

Closed
1 task
nunodsfernandes opened this issue Sep 7, 2023 · 1 comment
Closed
1 task

Multiple vulnerabilities found #631

nunodsfernandes opened this issue Sep 7, 2023 · 1 comment

Comments

@nunodsfernandes
Copy link

nunodsfernandes commented Sep 7, 2023

Is this a BUG REPORT or FEATURE REQUEST?:

  • [ x ] BUG
  • FEATURE

What happened:
Scans found multiple vulnerabilities on a vanilla Trudesk install.

Packages:

[REDACTED]

GH Reference
[REDACTED]

What did you expect to happen:
Any mitigation for these issues?

How to reproduce it (as minimally and precisely as possible):
This was the result of a scan conducted by an external tool (Wiz Scan).

Anything else we need to know?:

Environment:

  • Trudesk Version: 1.2.9
  • OS (e.g. from /etc/os-release): Ubuntu 20.04 LTS
  • Node.JS Version: v10.24.1
  • MongoDB Version: db version v3.6.23
  • Is this hosted on cloud.trudesk.io: No
@polonel
Copy link
Owner

polonel commented Sep 9, 2023

We utilize Synk for vulnerability patching/testing. There is already an active PR for Mongoose and the others are unverified.

Please email security vulnerabilities directly or report them on https://huntr.dev to prevent exposure before a patch is available from the third-party maintainer.

Thus I am deleting this issue and encourage you to report them to my email or https://huntr.dev

@polonel polonel closed this as completed Sep 9, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants