A Single Vulnerability Can Bring Down the JavaScript Ecosystem
landh.tech
landh.tech
There is a lot of JavaScript that does not use npm for good reasons (e.g. this, but also the rest of the disaster that is npm).
Also, you can target not just express but an even higher volume small library that most large projects depend on.
I don’t get how every comment so far has dismissed DoS as a serious issue.
I don't see the big security impact that the headline suggests, as active big-scale exploitation would likely be quickly noticed and fixed. The most interesting attack vector IMHO would be to block individual security fixes to packages on a small scale.
Fixed as in fixing the exploit that TFA is reporting? Isn’t that the point of their report?
It's interesting, but I share the thought that the impact is overstated.
Anyway, one properly mad technique shielding against all npm-related problems that I've seen being used was to include node_modules in the repo.
Terrible, yes, but was a real life-saver when the left-pad issue hit.
Terrible, yes, but was a real life saver
Ahhh... They're trying to sell themselves as security experts.