Vulnerable version of redoc package #46896
Unanswered
mhv-trackunit
asked this question in
General
Replies: 1 comment 2 replies
-
Yes - this is public information - redoc has this vulnerabily, Do you think airlfow is vulnerable and have a reproduction scenario? Then follow the security policy https://github.com/apache/airflow/security/policy and report it - including the scenario where it can be used to make harm. We would love to see such report - can you help with it plese @mhv-trackunit since you are interested in it? or maybe your company could pay security reserchers to investigate it? We would love to be able to get more insight |
Beta Was this translation helpful? Give feedback.
2 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
We have found out, that the version of redoc in airflow/www/package.json is set to “^2.0.0-rc.72”, which seems to have a prototype pollution vulnerability.
A link to Snyk documentation on the issue: https://security.snyk.io/vuln/SNYK-JS-REDOC-8664933
Beta Was this translation helpful? Give feedback.
All reactions