[SECURITY]: Announcing 1 Critical, 2 High and 1 Moderate advisories #46549
jamietanna
announced in
Maintainer announcements
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
We're announcing 4 GitHub Security Advisories (GHSAs) that affect the Renovate CLI.
There are 1 Critical, 2 High and 1 Moderate advisories.
It is recommended that you upgrade to a minimum of Renovate 44.79.0.
There are no planned backports of these fixes to previous major versions of Renovate.
CVE IDs have been requested for each of these.
Shared presets could bypass
allowedEnvandallowedHeadersallowedEnv) could be bypassed by using a shared presetallowedHeaders) could be bypassed by using a shared presetServer-Side Request Forgery via HTTP preset URLs in
extendsarray orcustomDatasourcesextendsarray orcustomDatasourcesminimumReleaseAgecould be bypassed when requesting a PR is rebasedminimumReleaseAgeinternal checksAll reactions