Discussion
Loading...

#Tag

Log in
  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
Jan :rust: :ferris: boosted
Soso
Soso
@sgued@pouet.chapril.org  ·  activity timestamp 2 weeks ago

Hey #Javascript folks, why does no one talking about the recent #React #CVE mentions defensive mechanisms like node's --disallow-code-generation-from-strings which from what I've seen would have prevented the RCE (there may be ways to exploit the prototype pollution but would make the attacker's job much harder).

There is also --disable-proto=delete but I don't know if it's practical.

Using Content Security Policies in the frontend is table stakes, why not also on the server?

#NodeJS #NextJS

  • Copy link
  • Flag this post
  • Block
Soso
Soso
@sgued@pouet.chapril.org  ·  activity timestamp 2 weeks ago

Hey #Javascript folks, why does no one talking about the recent #React #CVE mentions defensive mechanisms like node's --disallow-code-generation-from-strings which from what I've seen would have prevented the RCE (there may be ways to exploit the prototype pollution but would make the attacker's job much harder).

There is also --disable-proto=delete but I don't know if it's practical.

Using Content Security Policies in the frontend is table stakes, why not also on the server?

#NodeJS #NextJS

  • Copy link
  • Flag this post
  • Block
Konstantin 🔭
Konstantin 🔭
@konstantin@hachyderm.io  ·  activity timestamp 3 weeks ago

I will never understand the urge the use a library designed to provide reactive DOM updates as a server framework. Here I am, wasting time parametrising my queries while some are shipping unprotected “eval()” in what looks like a very abstracted gRPC service.

https://github.com/vercel/next.js/security/advisories/GHSA-9qr9-h5gf-34mp

#WebDev #React #NextJS

  • Copy link
  • Flag this post
  • Block

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About · Code of conduct · Privacy · Users · Instances
Bonfire social · 1.0.1-alpha.40 no JS en
Automatic federation enabled
Log in
  • Explore
  • About
  • Members
  • Code of Conduct