Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Replace cuid with cuid2 to fix CVE-2019-25010 & CVE-2020-25575 vulnerabilities #156

Open
ivangabriele opened this issue Sep 14, 2024 · 0 comments
Assignees
Labels
internal Internal issues and tasks. No direct impact on end-user. security:prevention Security vulnerability prevention fix.
Milestone

Comments

@ivangabriele
Copy link
Owner

ivangabriele commented Sep 14, 2024

cuid crate depends on base36 which itself depends on failure. There is apparently no directly threat since it seems to require overriding a private function. But the goal is to keep a 0 vulnerability track, as far as possible.

@ivangabriele ivangabriele added internal Internal issues and tasks. No direct impact on end-user. security:prevention Security vulnerability prevention fix. labels Sep 14, 2024
@ivangabriele ivangabriele added this to the v0.4 milestone Sep 14, 2024
@ivangabriele ivangabriele self-assigned this Sep 14, 2024
@ivangabriele ivangabriele changed the title Replace cuid in Core with cuid2 to fix CVE-2019-25010 & CVE-2020-25575 Replace cuid in Core with cuid2 to fix CVE-2019-25010 & CVE-2020-25575 vulnerabilities Sep 14, 2024
@ivangabriele ivangabriele changed the title Replace cuid in Core with cuid2 to fix CVE-2019-25010 & CVE-2020-25575 vulnerabilities Replace cuid with cuid2 to fix CVE-2019-25010 & CVE-2020-25575 vulnerabilities Sep 14, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
internal Internal issues and tasks. No direct impact on end-user. security:prevention Security vulnerability prevention fix.
Projects
None yet
Development

No branches or pull requests

1 participant