Skip to content
GitLab
    • Explore Projects Groups Snippets
Projects Groups Snippets
  • /
  • Help
    • Help
    • Support
    • Community forum
    • Submit feedback
    • Contribute to GitLab
  • Sign in / Register
  • C create-react-app
  • Project information
    • Project information
    • Activity
    • Labels
    • Members
  • Repository
    • Repository
    • Files
    • Commits
    • Branches
    • Tags
    • Contributors
    • Graph
    • Compare
  • Issues 1,547
    • Issues 1,547
    • List
    • Boards
    • Service Desk
    • Milestones
  • Merge requests 417
    • Merge requests 417
  • CI/CD
    • CI/CD
    • Pipelines
    • Jobs
    • Schedules
  • Deployments
    • Deployments
    • Environments
    • Releases
  • Packages and registries
    • Packages and registries
    • Package Registry
    • Infrastructure Registry
  • Monitor
    • Monitor
    • Incidents
  • Analytics
    • Analytics
    • Value stream
    • CI/CD
    • Repository
  • Wiki
    • Wiki
  • Snippets
    • Snippets
  • Activity
  • Graph
  • Create a new issue
  • Jobs
  • Commits
  • Issue Boards
Collapse sidebar
  • Meta
  • create-react-app
  • Issues
  • #11443
Closed
Open
Issue created 3 years ago by Administrator@rootContributor
  • New related issue

  • Report abuse to administrator

  • New related issue

  • Report abuse to administrator

`react-dev-utils`: Prototype Pollution in Immer

Closed

`react-dev-utils`: Prototype Pollution in Immer

Created by: SalGnt-Dev

Describe the bug

The react-dev-utils package uses a vulnerable version (v8.0.4) of Immer.

The fix, commit fa671e5, is part of the v9.0.6 release. The react-dev-utils package should use this specific version of Immer.

GitHub CVE

  • Prototype Pollution in immer (critical severity): CVE-2021-3757.
  • Prototype Pollution in immer (high severity): CVE-2021-23436.
  1. Oh no!

    You are trying to upload something other than an image. Please upload a .png, .jpg, .jpeg, .gif, .bmp, .tiff or .ico.

    Incoming!

    Drop your designs to start your upload.
Tasks
0

No tasks are currently assigned. Use tasks to break down this issue into smaller parts.

Linked items
0

Link issues together to show that they're related. Learn more.

Activity


  • Administrator
    Administrator @root · 3 years ago
    Author Contributor

    Created by: bpod

    I'm seeing this issue flagged as a high vulnerability in our pipeline scan as well. However, I don't think this version of immer would ever be included in a final build since its only used by react-scripts.

    Either way, Would love to see this addressed, thank you!

  • Administrator
    Administrator @root · 3 years ago
    Author Contributor

    Created by: theKashey

    The problem got multiplied by Storybook and potentially more projects which use react-dev-utils

  • Administrator
    Administrator @root · 3 years ago
    Author Contributor

    Created by: DaisyyKM

    Vulnerability is still there because we are not getting the updated version Linking my comment from PR http://metis.lti.cs.cmu.edu:8023/facebook/create-react-app/-/merge_requests/11364#issuecomment-938057494

  • Administrator
    Administrator @root · 3 years ago
    Author Contributor

    Created by: furdzik

    Any update on this?

    In my project also react-dev-utils@11.0.4 has immer as dependency but still in version 8.0.1.

  • Administrator
    Administrator @root · 3 years ago
    Author Contributor

    Created by: ziaulrehman40

    This is marked critical, should be fixed on priority

  • Administrator
    Administrator @root · 3 years ago
    Author Contributor

    Created by: hijikiman

    This problem seems to have been resolved in release 5.0.0

Please register or sign in to reply
0 Assignees
None
Assign to
Labels
2
issue: bug report needs triage
2
issue: bug report needs triage
    Assign labels
  • Manage project labels

Milestone
No milestone
None
Due date
None
None
None
Time tracking
No estimate or time spent
Confidentiality
Not confidential
Not confidential

You are going to turn on confidentiality. Only project members with at least the Reporter role, the author, and assignees can view or be notified about this issue.

Lock issue
Unlocked
1
1 participant
Administrator
Reference: facebook/create-react-app#11443

Menu

Explore Projects Groups Snippets