Skip to content

chore(deps): update dependency @nestjs/core to v9 [security]#128

Open
renovate[bot] wants to merge 1 commit intomasterfrom
renovate/npm-nestjs-core-vulnerability
Open

chore(deps): update dependency @nestjs/core to v9 [security]#128
renovate[bot] wants to merge 1 commit intomasterfrom
renovate/npm-nestjs-core-vulnerability

Conversation

@renovate
Copy link
Copy Markdown
Contributor

@renovate renovate Bot commented Aug 6, 2024

This PR contains the following updates:

Package Change Age Confidence
@nestjs/core (source) 8.4.49.0.5 age confidence

@​nestjs/core vulnerable to Information Exposure via StreamableFile pipe

CVE-2023-26108 / GHSA-4jpv-8r57-pv7j

More information

Details

Versions of the package @​nestjs/core before 9.0.5 are vulnerable to Information Exposure via the StreamableFile pipe. Exploiting this vulnerability is possible when the client cancels a request while it is streaming a StreamableFile, the stream wrapped by the StreamableFile will be kept open.

Severity

  • CVSS Score: 5.3 / 10 (Medium)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

nestjs/nest (@​nestjs/core)

v9.0.5

Compare Source

v9.0.5 (2022-07-20)

Bug fixes
Enhancements
  • microservices
  • platform-express, platform-fastify
Dependencies
Committers: 4

v9.0.4

Compare Source

v9.0.3

Compare Source

v9.0.2

Compare Source

v9.0.2

Bug fixes
Enhancements
Dependencies
Committers: 3

v9.0.1

Compare Source

v9.0.0

Compare Source

v9.0.0 (2022-07-08)

Article: https://trilon.io/blog/nestjs-9-is-now-available
Migration guide: https://docs.nestjs.com/migration-guide
Features
Bug fixes
Enhancements
Dependencies
Committers: 13

v8.4.7

Compare Source

v8.4.7 (2022-06-14)
Enhancements
  • microservices
  • common
Dependencies
Committers: 5

v8.4.6

Compare Source

v8.4.5

Compare Source

v8.4.5 (2022-05-13)
Bug fixes
Enhancements
Dependencies
Committers: 6

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • ""
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot requested a review from toondaey as a code owner August 6, 2024 10:27
@renovate renovate Bot added dependencies Dependencies modifications major-update labels Aug 6, 2024
@renovate renovate Bot changed the title chore(deps): update dependency @nestjs/core to v9 [security] chore(deps): update dependency @nestjs/core to v9 [security] - autoclosed Mar 27, 2026
@renovate renovate Bot closed this Mar 27, 2026
@renovate renovate Bot deleted the renovate/npm-nestjs-core-vulnerability branch March 27, 2026 01:32
@renovate renovate Bot changed the title chore(deps): update dependency @nestjs/core to v9 [security] - autoclosed chore(deps): update dependency @nestjs/core to v9 [security] Mar 30, 2026
@renovate renovate Bot reopened this Mar 30, 2026
@renovate renovate Bot force-pushed the renovate/npm-nestjs-core-vulnerability branch 2 times, most recently from fa4f003 to 8aeec3c Compare March 30, 2026 18:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Dependencies modifications major-update

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants