From 1cc9667e2432d1d27c2647b86e42707a2e78e4c3 Mon Sep 17 00:00:00 2001 From: ruzell22 Date: Wed, 29 Mar 2023 11:05:52 +0800 Subject: [PATCH] fix(cmd-api-server): mitigate CVE-2022-24434 and CVE-2022-24999 #2039 fixes: #2039 related to: #2241 Verified that these changes will fix the vulnerabilities in cactus-cmd-api-server in addition to the following CVE IDs: - CVE-2022-24434 - CVE-2022-24999 (express) - CVE-2022-24999 (qs) Co-authored-by: Peter Somogyvari Signed-off-by: ruzell22 Signed-off-by: Peter Somogyvari --- packages/cactus-core/package.json | 4 ++-- packages/cactus-plugin-ledger-connector-besu/package.json | 2 +- 2 files changed, 3 insertions(+), 3 deletions(-) diff --git a/packages/cactus-core/package.json b/packages/cactus-core/package.json index 25f91e7151..8f494cf183 100644 --- a/packages/cactus-core/package.json +++ b/packages/cactus-core/package.json @@ -52,9 +52,9 @@ "dependencies": { "@hyperledger/cactus-common": "1.2.0", "@hyperledger/cactus-core-api": "1.2.0", - "express": "4.17.1", + "express": "4.17.3", "express-jwt-authz": "2.4.1", - "express-openapi-validator": "4.12.12", + "express-openapi-validator": "4.13.8", "typescript-optional": "2.0.1" }, "devDependencies": { diff --git a/packages/cactus-plugin-ledger-connector-besu/package.json b/packages/cactus-plugin-ledger-connector-besu/package.json index 9f89b1cad1..8464ad6ffd 100644 --- a/packages/cactus-plugin-ledger-connector-besu/package.json +++ b/packages/cactus-plugin-ledger-connector-besu/package.json @@ -57,7 +57,7 @@ "@hyperledger/cactus-core": "1.2.0", "@hyperledger/cactus-core-api": "1.2.0", "axios": "0.21.4", - "express": "4.17.1", + "express": "4.17.3", "joi": "17.4.2", "openapi-types": "9.1.0", "prom-client": "13.2.0",