Async: lodash์—์„œ ๋ฐœ๊ฒฌ๋œ ์ค‘๊ฐ„ ์‹ฌ๊ฐ๋„ ์ทจ์•ฝ์ 

์— ๋งŒ๋“  2019๋…„ 02์›” 04์ผ  ยท  4์ฝ”๋ฉ˜ํŠธ  ยท  ์ถœ์ฒ˜: caolan/async

snyk ๋Š” ์ข…์†์„ฑ ์ค‘ ํ•˜๋‚˜์ธ lodash 4.17.5 ์— ๋Œ€ํ•œ ์ •๊ทœ์‹ ์„œ๋น„์Šค ๊ฑฐ๋ถ€ ์ทจ์•ฝ์ ์„ ๋ณด๊ณ ํ•ฉ๋‹ˆ๋‹ค.

โœ— Medium severity vulnerability found in lodash
  Description: Regular Expression Denial of Service (ReDoS)
  Info: https://snyk.io/vuln/SNYK-JS-LODASH-73639
  Introduced through: [email protected]
  From: [email protected] > [email protected]
  Remediation:
    Your dependencies are out of date, otherwise you would be using a newer version of lodash. 
    Try deleting node_modules, reinstalling and running `snyk test` again. If the problem persists, one of your dependencies may be bundling outdated modules.

๊ทธ๋ฆฌ๊ณ 

Analyzing npm dependencies for package.json
Querying vulnerabilities database...
Tested 255 dependencies for known vulnerabilities, found 3 vulnerabilities, 23 vulnerable paths.

? 2 vulnerabilities introduced via [email protected]
- info: https://snyk.io/package/npm/async/2.6.1

๋ฏธ๋ฆฌ ๊ฐ์‚ฌ๋“œ๋ฆฝ๋‹ˆ๋‹ค!

๊ฐ€์žฅ ์œ ์šฉํ•œ ๋Œ“๊ธ€

lodash๋ฅผ ์—…๋ฐ์ดํŠธํ•˜๋Š” ๊ฒƒ์€ ๋ฌธ์ œ๊ฐ€ ๋˜์ง€ ์•Š์•˜์œผ๋ฉฐ ์—…๋ฐ์ดํŠธ์™€ ํ•จ๊ป˜ v2.6.2๋ฅผ ๊ฒŒ์‹œํ–ˆ์Šต๋‹ˆ๋‹ค.

๋ชจ๋“  4 ๋Œ“๊ธ€

์ถฉ๋Œ

์šฐ๋ฆฌ๋Š” ๊ทธ ๋ฐฉ๋ฒ•์„ ์‚ฌ์šฉํ•˜์ง€ ์•Š์œผ๋ฏ€๋กœ ์šฐ๋ฆฌ์—๊ฒŒ ์ ์šฉ๋˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค. ์šฐ๋ฆฌ๋Š” lodash๋ฅผ ์ œ๊ฑฐํ–ˆ์Šต๋‹ˆ๋‹ค.
v3.0. ๋งˆ์ด๋„ˆ์—์„œ ๋งˆ์ด๊ทธ๋ ˆ์ด์…˜ํ•˜๋Š” ๋ฐ ๋ช‡ ๊ฐ€์ง€ ๋ฌธ์ œ๊ฐ€ ์žˆ๋‹ค๊ณ  ์ƒ๊ฐํ•ฉ๋‹ˆ๋‹ค.
Async์˜ 2.x ๋ผ์ธ์— ์žˆ๋Š” lodash ๋ฒ„์ „์ž…๋‹ˆ๋‹ค.

2019๋…„ 2์›” 8์ผ ๊ธˆ์š”์ผ ์˜ค์ „ 2์‹œ 12๋ถ„ Daniel Scalzi < [email protected] ์ž‘์„ฑ:

์ถฉ๋Œ

โ€”
์ด ์Šค๋ ˆ๋“œ์— ๊ฐ€์ž…ํ–ˆ๊ธฐ ๋•Œ๋ฌธ์— ์ด ๋ฉ”์‹œ์ง€๋ฅผ ๋ฐ›๊ณ  ์žˆ์Šต๋‹ˆ๋‹ค.
์ด ์ด๋ฉ”์ผ์— ์ง์ ‘ ๋‹ต์žฅํ•˜๊ณ  GitHub์—์„œ ํ™•์ธํ•˜์„ธ์š”.
https://github.com/caolan/async/issues/1620#issuecomment-461784127 ๋˜๋Š” ์Œ์†Œ๊ฑฐ
์Šค๋ ˆ๋“œ
https://github.com/notifications/unsubscribe-auth/AAiEbmULsTIq6AwY5RHZJNcM60O1Lw7tks5vLWmygaJpZM4ah0sH
.

๊ฐ„๋‹จํ•œ ํŒจ์น˜ ์—…๋ฐ์ดํŠธ๊ฐ€ ํŠธ๋ฆญ์„ ์ˆ˜ํ–‰ํ•  ๊ฒƒ์ด๋ผ๊ณ  ์ƒ๊ฐํ•ฉ๋‹ˆ๋‹ค.

image

๋˜๋Š” v3.0.0์„ npm์—์„œ latest ๋กœ ์„ค์ •ํ•ฉ๋‹ˆ๋‹ค. ํ˜„์žฌ next ์ด๊ณ  npm outdated ๋กœ ํ‘œ์‹œ๋˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค.

lodash๋ฅผ ์—…๋ฐ์ดํŠธํ•˜๋Š” ๊ฒƒ์€ ๋ฌธ์ œ๊ฐ€ ๋˜์ง€ ์•Š์•˜์œผ๋ฉฐ ์—…๋ฐ์ดํŠธ์™€ ํ•จ๊ป˜ v2.6.2๋ฅผ ๊ฒŒ์‹œํ–ˆ์Šต๋‹ˆ๋‹ค.

์ด ํŽ˜์ด์ง€๊ฐ€ ๋„์›€์ด ๋˜์—ˆ๋‚˜์š”?
0 / 5 - 0 ๋“ฑ๊ธ‰