Vulnerable transitive dependency: axios 0.21.4 via adal-node (CVE-2023-45857)
Nobody has claimed this yet.
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 45/100
- Issue type
- Bug
- Clarity
- Mostly clear
- Activity status
- Quiet
- Tech stack
- typescript
- Domain
- authentication, security
Research direction
Start by inspecting node_modules/adal-node/node_modules/axios/package.json and the project’s dependency configuration to trace how axios 0.21.4 is installed. Compare the existing adal-node dependency with the proposed @azure/msal-node migration or an override approach. Done means the extension no longer bundles the vulnerable axios version and the CVE is closed.
Written by the indexing model from the issue text.
Description
Title: Vulnerable transitive dependency: axios 0.21.4 via adal-node (CVE-2023-45857)
Body:
The extension (currently latest, v6.8.1) bundles [email protected], which pins
axios: "^0.21.1". This resolves to [email protected], which is affected by
CVE-2023-45857 (axios leaks the XSRF-TOKEN header to third-party hosts
on cross-origin redirects, fixed in axios 1.6.0).
Path in the installed extension:
node_modules/adal-node/node_modules/axios/package.json → version 0.21.4
Since adal-node is deprecated in favor of MSAL and hasn't been updated
upstream, this can't be resolved by bumping a version range alone.
Could the extension move off adal-node to @azure/msal-node (as Microsoft
recommends for its own deprecated library), or otherwise dedupe/override the
axios version to close this out?
Flagged by our internal security/IT review.
- Dominant language
- TypeScript
- Stars
- 290
- Forks
- 46
- Avg merge
- 6m
- Merged PRs (30d)
- 1
Getting set up
We have not checked this project's setup files yet. Start from its README, and see our first-contribution guide for the general steps.
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from microsoft/DurableFunctionsMonitor
-
Needs: Triage :mag:
Difficulty 3/5 1-2 days Newbie friendliness 40/100
microsoft/DurableFunctionsMonitor#324 · 1 reaction ·
-
Needs: Triage :mag:
Difficulty 3/5 1-2 days Newbie friendliness 55/100
-
Needs: Triage :mag:
Difficulty 4/5 3-5 days Newbie friendliness 35/100
microsoft/DurableFunctionsMonitor#316 · 4 comments ·
-
Needs: Triage :mag:
Difficulty 1/5 Under an hour Newbie friendliness 55/100
-
Needs: Triage :mag:
Difficulty 4/5 3-5 days Newbie friendliness 35/100
All issues in microsoft/DurableFunctionsMonitor
Similar issues
-
Difficulty 1/5 Under an hour Newbie friendliness 72/100
betagouv/mon-entreprise#4699 ·
Maintainers usually reply within 3 days
-
bug
Difficulty 2/5 1-3 hours Newbie friendliness 82/100
jaegertracing/jaeger-ui#4547 · 3 comments ·
Maintainers usually reply within 1 day
-
ai-driven-qa
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
linagora/twake-calendar-frontend#1467 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
need4deed-org/sdk#267 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
auth0/universal-login#414 ·
Maintainers usually reply within 1 day