Commit 1297e2c
authored
chore(deps): update dependency koa to v2.16.1 [security] (#308)
This PR contains the following updates:
| Package | Change | Age | Adoption | Passing | Confidence |
|---|---|---|---|---|---|
| [koa](https://redirect.github.com/koajs/koa) | [`2.16.0` ->
`2.16.1`](https://renovatebot.com/diffs/npm/koa/2.16.0/2.16.1) |
[](https://docs.renovatebot.com/merge-confidence/)
|
[](https://docs.renovatebot.com/merge-confidence/)
|
[](https://docs.renovatebot.com/merge-confidence/)
|
[](https://docs.renovatebot.com/merge-confidence/)
|
### GitHub Vulnerability Alerts
####
[CVE-2025-32379](https://redirect.github.com/koajs/koa/security/advisories/GHSA-x2rg-q646-7m2v)
### Summary
In koa < 2.16.1 and < 3.0.0-alpha.5, passing untrusted user input to
ctx.redirect() even after sanitizing it, may execute javascript code on
the user who use the app.
### Patches
This issue is patched in 2.16.1 and 3.0.0-alpha.5.
### PoC
https://gist.github.com/linhnph05/03d677b183636af206ff781bdd19701a
### Impact
1. Redirect user to another phishing site
2. Make request to another endpoint of the application based on user's
cookie
3. Steal user's cookie
---
### Release Notes
<details>
<summary>koajs/koa (koa)</summary>
###
[`v2.16.1`](https://redirect.github.com/koajs/koa/releases/tag/v2.16.1)
[Compare
Source](https://redirect.github.com/koajs/koa/compare/2.16.0...v2.16.1)
fix: don't render redirect values in anchor ref
</details>
---
### Configuration
📅 **Schedule**: Branch creation - "" (UTC), Automerge - At any time (no
schedule defined).
🚦 **Automerge**: Disabled by config. Please merge this manually once you
are satisfied.
♻ **Rebasing**: Whenever PR is behind base branch, or you tick the
rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about these
updates again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check
this box
---
This PR was generated by [Mend Renovate](https://mend.io/renovate/).
View the [repository job
log](https://developer.mend.io/github/mnahkies/openapi-code-generator).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiIzOS4yMzguMCIsInVwZGF0ZWRJblZlciI6IjM5LjIzOC4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6W119-->
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>1 parent 0a0f623 commit 1297e2c
1 file changed
Lines changed: 3 additions & 3 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.
0 commit comments