VDB
Sign up
HIGH8.6

GHSA-vc52-gwm3-8v2f

Missing "--allow-net" permission check for built-in Node modules

Details

### Impact

Outbound HTTP requests made using the built-in "node:http" or "node:https" modules are incorrectly not checked against the network permission allow list (`--allow-net`). Dependencies relying on these built-in modules are subject to the vulnerability too.

Users of Deno versions prior to 1.34.0 are unaffected. Deno Deploy users are unaffected.

### Patches

This problem has been patched in Deno v1.34.1 and all users are recommended to update to this version.

### Workarounds

No workaround is available for this issue.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/deno
Introduced in: 1.34.0Fixed in: 1.34.1

Upgrade deno to 1.34.1 or newer (ecosystem crates.io).

crates.io/deno_runtime
Introduced in: 0.114.0Fixed in: 0.115.0

Upgrade deno_runtime to 0.115.0 or newer (ecosystem crates.io).

References