Project

General

Profile

Actions

Bug #29687

open

Ignore CVE-2026-8657 in rudder 9.0

Bug #29687: Ignore CVE-2026-8657 in rudder 9.0

Added by Véronique HAYAERT 5 days ago. Updated about 8 hours ago.

Status:
Pending release
Priority:
N/A
Category:
-
Target version:
Severity:
UX impact:
User visibility:
Effort required:
Priority:
0
Name check:
To do
Fix check:
Checked
Regression:
No

Description

rudder 9.0 currently has the jsondiffpatch dependency in version 0.5.0, which is vulnerable to CVE-2026-8657

however, we no longer accept non-ES JavaScript modules as per https://github.com/Normation/rudder/pull/6460, and CVE-2026-8657 involves the jsondiffpatch.patch() function, which is unused.

hence, we can ignore CVE-2026-8657

Updated by Véronique HAYAERT 4 days ago Actions #1

  • Status changed from New to In progress
  • Assignee set to Véronique HAYAERT

Updated by Véronique HAYAERT 4 days ago Actions #2

  • Status changed from In progress to Pending technical review
  • Assignee changed from Véronique HAYAERT to Clark ANDRIANASOLO
  • Pull Request set to https://github.com/Normation/rudder/pull/7465

Updated by Véronique HAYAERT 4 days ago Actions #3

  • Status changed from Pending technical review to Pending release

Updated by Clark ANDRIANASOLO about 8 hours ago Actions #4

  • Fix check changed from To do to Checked
Actions

Also available in: PDF Atom