QID 980785
QID 980785: Nodejs (npm) Security Update for @node-red/runtime (GHSA-xp9c-82x8-7f67)
Security update has been released for @node-red/runtime to fix the vulnerability.
Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
Node-RED 1.2.7 and earlier contains a Prototype Pollution vulnerability in the admin API. A badly formed request can modify the prototype of the default JavaScript Object with the potential to affect the default behaviour of the Node-RED runtime.
Solution
The vulnerability is patched in the 1.2.8 release.Workaround:
A workaround is to ensure only authorised users are able to access the editor url.
A workaround is to ensure only authorised users are able to access the editor url.
Vendor References
- GHSA-xp9c-82x8-7f67 -
github.com/advisories/GHSA-xp9c-82x8-7f67
CVEs related to QID 980785
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-xp9c-82x8-7f67 | @node-red/runtime |
|