chore(deps): update dependency fastify to v4.10.2 [security] - autoclosed#15
Closed
renovate[bot] wants to merge 1 commit into
Closed
chore(deps): update dependency fastify to v4.10.2 [security] - autoclosed#15renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
9df1130 to
75080be
Compare
75080be to
2226b80
Compare
429e97b to
263e060
Compare
0f6dd51 to
08e6671
Compare
08e6671 to
82a2da6
Compare
82a2da6 to
1d16fc5
Compare
1d16fc5 to
8747271
Compare
efee25d to
4cfebd6
Compare
4cfebd6 to
bf53158
Compare
cfbc7ed to
88c1339
Compare
ddb2bef to
7a38976
Compare
ff77dd8 to
f759a87
Compare
f759a87 to
22a7152
Compare
22a7152 to
f4a7da1
Compare
f4a7da1 to
b16c48d
Compare
b16c48d to
08b99fb
Compare
881daa5 to
10dab03
Compare
10dab03 to
5e3bbef
Compare
5e3bbef to
8354407
Compare
8354407 to
36118ff
Compare
36118ff to
b89cc25
Compare
b89cc25 to
d6a7733
Compare
d6a7733 to
a41b08e
Compare
a41b08e to
623d6d5
Compare
623d6d5 to
1d5903c
Compare
1d5903c to
e149d89
Compare
e149d89 to
5bdbb38
Compare
5bdbb38 to
5aba70e
Compare
5aba70e to
36155c0
Compare
bff1fe9 to
255b845
Compare
255b845 to
c6d7666
Compare
c6d7666 to
cd85bee
Compare
cd85bee to
87811cc
Compare
87811cc to
ea62f1c
Compare
ea62f1c to
560439e
Compare
560439e to
e0f1953
Compare
e0f1953 to
9fa3c77
Compare
9fa3c77 to
80aa0ad
Compare
80aa0ad to
407d052
Compare
407d052 to
1dc3c9d
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
4.2.0→4.10.2GitHub Vulnerability Alerts
CVE-2022-39288
Impact
An attacker can send an invalid
Content-Typeheader that can cause the application to crash, leading to a possible Denial of Service attack. Only the v4.x line is affected.(This was updated: upon a close inspection, v3.x is not affected after all).
Patches
Yes, update to
> v4.8.0.Workarounds
You can reject the malicious content types before the body parser enters in action.
References
See the HackerOne report #1715536
For more information
Fastify security policy
CVE-2022-41919
Impact
The attacker can use the incorrect
Content-Typeto bypass thePre-Flightchecking offetch.fetch()requests with Content-Type’s essence as "application/x-www-form-urlencoded", "multipart/form-data", or "text/plain", could potentially be used to invoke routes that only acceptsapplication/jsoncontent type, thus bypassing any CORS protection, and therefore they could lead to a Cross-Site Request Forgery attack.Patches
For
4.xusers, please update to at least4.10.2For
3.xusers, please update to at least3.29.4Workarounds
Implement Cross-Site Request Forgery protection using
@fastify/csrf.References
Check out the HackerOne report: https://hackerone.com/reports/1763832.
For more information
Fastify security policy
Release Notes
fastify/fastify (fastify)
v4.10.2Compare Source
and CVE-2022-41919
Full Changelog: fastify/fastify@v4.10.1...v4.10.2
v4.10.1Compare Source
What's Changed
New Contributors
Full Changelog: fastify/fastify@v4.10.0...v4.10.1
v4.10.0Compare Source
What's Changed
nullorundefinedvalues passed as fn by @metcoder95 in #4367New Contributors
Full Changelog: fastify/fastify@v4.9.2...v4.10.0
v4.9.2Compare Source
What's Changed
Full Changelog: fastify/fastify@v4.9.1...v4.9.2
v4.9.1Compare Source
What's Changed
New Contributors
Full Changelog: fastify/fastify@v4.9.0...v4.9.1
v4.9.0Compare Source
What's Changed
New Contributors
Full Changelog: fastify/fastify@v4.8.1...v4.9.0
v4.8.1Compare Source
This release fixes GHSA-455w-c45v-86rg for the v4.x line.
This is a HIGH vulnerability that can lead to a crash, resulting in a total loss of availability.
The CVE for this vulnerability is CVE-2022-39288.
Full Changelog: fastify/fastify@v4.8.0...v4.8.1
v4.8.0Compare Source
What's Changed
New Contributors
Full Changelog: fastify/fastify@v4.7.0...v4.8.0
v4.7.0Compare Source
What's Changed
@fastify/one-line-loggerby @nooreldeensalah in #4293New Contributors
Full Changelog: fastify/fastify@v4.6.0...v4.7.0
v4.6.0Compare Source
What's Changed
fastify.httpsto benullby @SuperchupuDev in #4226b27edacto 3 by @dependabot in #4244b27edacto 3" by @climba03003 in #4245Ecosystem.mdlinter to check for improper module name patterns by @nooreldeensalah in #4257Ecosystem.mdlinter to lint all sections by @nooreldeensalah in #4258New Contributors
Full Changelog: fastify/fastify@v4.5.3...v4.6.0
v4.5.3Compare Source
What's Changed
Full Changelog: fastify/fastify@v4.5.2...v4.5.3
v4.5.2Compare Source
What's Changed
Full Changelog: fastify/fastify@v4.5.1...v4.5.2
v4.5.1Compare Source
What's Changed
Full Changelog: fastify/fastify@v4.5.0...v4.5.1
v4.5.0Compare Source
What's Changed
onSendexample by @Fdawgs in #4188New Contributors
Full Changelog: fastify/fastify@v4.4.0...v4.5.0
v4.4.0Compare Source
What's Changed
validateInputby @metcoder95 in #4151New Contributors
Full Changelog: fastify/fastify@v4.3.0...v4.4.0
v4.3.0Compare Source
What's Changed
FastifyListenOptionsin top-level types by @kyranet in #4135request.validatetorequest.validateInputby @metcoder95 in #4139New Contributors
Full Changelog: fastify/fastify@v4.2.1...v4.3.0
v4.2.1Compare Source
What's Changed
FastifySchemaValidationErrortype insufficient by @BlackHole1 in #4094listenoptions and export it by @kyranet in #4013New Contributors
Full Changelog: fastify/fastify@v4.2.0...v4.2.1
Configuration
📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.