Skip to content

GHSA-2mhj-xmf4-pr8m - Affected versions are too broad #5054

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Closed
FrederikBolding opened this issue Dec 4, 2024 · 3 comments
Closed

GHSA-2mhj-xmf4-pr8m - Affected versions are too broad #5054

FrederikBolding opened this issue Dec 4, 2024 · 3 comments

Comments

@FrederikBolding
Copy link

The affected versions for GHSA-2mhj-xmf4-pr8m are too broad currently flagging all available versions of the package.

The correct versions to flag are: 1.95.6 and 1.95.7, these are also the only versions of the package that have been taken down from NPM. One of the publishers of the package was phished causing the two versions mentioned previously to be published containing malware. There are no known issues with any other versions of the package AFAIK.

Sources:
https://github.com/solana-labs/solana-web3.js/releases/tag/v1.95.8
https://x.com/anza_xyz/status/1864085236432134264
https://x.com/trentdotsol/status/1864053347461771321

@mackyfer
Copy link

mackyfer commented Dec 4, 2024

I second this. Putting the version number so broad is problematic and misinformation.

@shelbyc
Copy link
Contributor

shelbyc commented Dec 4, 2024

👋 Hi @FrederikBolding and @mackyfer, GHSA-2mhj-xmf4-pr8m has been updated with narrower version range information. In addition, the maintainers of @solana/web3.js published GHSA-jcxm-7wvp-g6p5 with the narrower version range information included. Thanks for the feedback and enjoy the rest of your day!

@shelbyc shelbyc closed this as completed Dec 4, 2024
@FrederikBolding
Copy link
Author

Appreciate it, thanks!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants