You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The provided Node package (externals/nodeXX) contains the node-ip version <2.0.1 which might allow SSRF because some IP addresses (such as 0x7f.1) are improperly categorized as globally routable via isPublic. (https://nvd.nist.gov/vuln/detail/CVE-2023-42282)
When action-runner is deployed as ECS task this is reported as a finding/vulnerability
Runner Version and Platform
3.15.0 Linux (probably all other platforms as well)
The text was updated successfully, but these errors were encountered:
It seems that both the action-runner images (v2.314.1 and possibly v2.315.0, if details haven't changed) are still facing the CVE-2023-42282 vulnerability associated with the 'ip' package. The 'ip' package version remains below 2.0.1, making it vulnerable. Could you help us address this issue?
The provided Node package (externals/nodeXX) contains the node-ip version
<2.0.1
which might allow SSRF because some IP addresses (such as 0x7f.1) are improperly categorized as globally routable via isPublic. (https://nvd.nist.gov/vuln/detail/CVE-2023-42282)When action-runner is deployed as ECS task this is reported as a finding/vulnerability
Runner Version and Platform
3.15.0 Linux (probably all other platforms as well)
The text was updated successfully, but these errors were encountered: