Skip to content
This repository was archived by the owner on Aug 29, 2024. It is now read-only.

fix(deps): update dependency class-validator to v0.14.0 [security]#39

Closed
renovate[bot] wants to merge 1 commit intomainfrom
renovate/npm-class-validator-vulnerability
Closed

fix(deps): update dependency class-validator to v0.14.0 [security]#39
renovate[bot] wants to merge 1 commit intomainfrom
renovate/npm-class-validator-vulnerability

Conversation

@renovate
Copy link
Copy Markdown

@renovate renovate bot commented Jan 20, 2023

Mend Renovate

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
class-validator 0.13.2 -> 0.14.0 age adoption passing confidence

GitHub Vulnerability Alerts

CVE-2019-18413

In TypeStack class-validator, validate() input validation can be bypassed because certain internal attributes can be overwritten via a conflicting name. Even though there is an optional forbidUnknownValues parameter that can be used to reduce the risk of this bypass, this option is not documented and thus most developers configure input validation in the vulnerable default manner. With this vulnerability, attackers can launch SQL Injection or XSS attacks by injecting arbitrary malicious input.

The default settings for forbidUnknownValues has been changed to true in 0.14.0.

NOTE: a software maintainer agrees with the "is not documented" finding but suggests that much of the responsibility for the risk lies in a different product.


Release Notes

typestack/class-validator

v0.14.0

Compare Source


Configuration

📅 Schedule: Branch creation - "" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate. View repository job log here.

@renovate renovate bot changed the title chore(deps): update dependency class-validator to 0.14.0 [security] fix(deps): update dependency class-validator to v0.14.0 [security] Mar 16, 2023
@renovate renovate bot changed the title fix(deps): update dependency class-validator to v0.14.0 [security] chore(deps): update dependency class-validator to 0.14.0 [security] Mar 17, 2023
@renovate renovate bot changed the title chore(deps): update dependency class-validator to 0.14.0 [security] fix(deps): update dependency class-validator to v0.14.0 [security] Mar 17, 2023
@renovate renovate bot changed the title fix(deps): update dependency class-validator to v0.14.0 [security] chore(deps): update dependency class-validator to 0.14.0 [security] Apr 9, 2023
@renovate renovate bot changed the title chore(deps): update dependency class-validator to 0.14.0 [security] fix(deps): update dependency class-validator to v0.14.0 [security] Apr 9, 2023
@renovate renovate bot force-pushed the renovate/npm-class-validator-vulnerability branch from e77b797 to 7bcdaf4 Compare April 9, 2023 12:57
@renovate renovate bot force-pushed the renovate/npm-class-validator-vulnerability branch from 7bcdaf4 to dd32ab9 Compare April 9, 2023 13:07
@stale
Copy link
Copy Markdown

stale bot commented Jun 8, 2023

This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs. Thank you for your contributions.

@stale stale bot added the wontfix This will not be worked on label Jun 8, 2023
@stale stale bot closed this Jun 15, 2023
@renovate
Copy link
Copy Markdown
Author

renovate bot commented Jun 15, 2023

Renovate Ignore Notification

Because you closed this PR without merging, Renovate will ignore this update (0.14.0). You will get a PR once a newer version is released. To ignore this dependency forever, add it to the ignoreDeps array of your Renovate config.

If you accidentally closed this PR, or if you changed your mind: rename this PR to get a fresh replacement PR.

@renovate renovate bot deleted the renovate/npm-class-validator-vulnerability branch June 15, 2023 19:53
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

wontfix This will not be worked on

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants