Skip to content

Update tunnel-ssh dependency for vulnerability CVE-2023-48795 #830

Description

@coruscating

I'm submitting a...

  • Bug report
  • Feature request
  • Question

Current behavior

The vulnerability CVE-2023-48795 requires ssh2 1.15 and above to fix: mscdex/ssh2#1354

The tunnel-ssh 4.x series, which is a dependency of db-migrate, only supports ssh2 up to 1.4.0: #755. This CVE can be resolved for db-migrate if the tunnel-ssh dependency is upgraded to 5.x (or if tunnel-ssh updates its 4.x dependencies, but it's been a year since 5.x was released).

Expected behavior

The security vulnerability should be addressed.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions