Skip to content

Update tunnel-ssh dependency for vulnerability CVE-2023-48795 #830

Open
@coruscating

Description

@coruscating

I'm submitting a...

  • Bug report
  • Feature request
  • Question

Current behavior

The vulnerability CVE-2023-48795 requires ssh2 1.15 and above to fix: mscdex/ssh2#1354

The tunnel-ssh 4.x series, which is a dependency of db-migrate, only supports ssh2 up to 1.4.0: #755. This CVE can be resolved for db-migrate if the tunnel-ssh dependency is upgraded to 5.x (or if tunnel-ssh updates its 4.x dependencies, but it's been a year since 5.x was released).

Expected behavior

The security vulnerability should be addressed.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions