Skip to content

Update dependency firebase to v10 [SECURITY]#328

Open
renovate[bot] wants to merge 1 commit intodevelopfrom
renovate/npm-firebase-vulnerability
Open

Update dependency firebase to v10 [SECURITY]#328
renovate[bot] wants to merge 1 commit intodevelopfrom
renovate/npm-firebase-vulnerability

Conversation

@renovate
Copy link
Copy Markdown
Contributor

@renovate renovate Bot commented Nov 18, 2024

This PR contains the following updates:

Package Change Age Confidence
firebase (source, changelog) ^9.10.0^10.0.0 age confidence

Firebase JavaScript SDK allows attackers to manipulate the "_authTokenSyncURL" to point to their own server

CVE-2024-11023 / GHSA-3wf4-68gx-mph8

More information

Details

Firebase JavaScript SDK utilizes a "FIREBASE_DEFAULTS" cookie to store configuration data, including an "_authTokenSyncURL" field used for session synchronization. If this cookie field is preset via an attacker by any other method, the attacker can manipulate the "_authTokenSyncURL" to point to their own server and it would allow am actor to capture user session data transmitted by the SDK. We recommend upgrading Firebase JS SDK at least to 10.9.0.

Severity

  • CVSS Score: 5.2 / 10 (Medium)
  • Vector String: CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:A/VC:L/VI:L/VA:L/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

firebase/firebase-js-sdk (firebase)

v10.9.0

Compare Source

v10.8.1

Compare Source

v10.8.0

Compare Source

v10.7.2

Compare Source

v10.7.1

Compare Source

v10.7.0

Compare Source

v10.6.0

Compare Source

v10.5.2

Compare Source

v10.5.1

Compare Source

v10.5.0

Compare Source

v10.4.0

Compare Source

v10.3.1

Compare Source

v10.3.0

Compare Source

v10.2.0

Compare Source

v10.1.0

Compare Source

v10.0.0

Compare Source

v9.23.0

Compare Source

v9.22.2

Compare Source

v9.22.1

Compare Source

v9.22.0

Compare Source

v9.21.0

Compare Source

v9.20.0

Compare Source

v9.19.1

Compare Source

v9.19.0

Compare Source

v9.18.0

Compare Source

v9.17.2

Compare Source

v9.17.1

Compare Source

v9.17.0

Compare Source

v9.16.0

Compare Source

v9.15.0

Compare Source

v9.14.0

Compare Source

v9.13.0

Compare Source

v9.12.1

Compare Source

v9.12.0

Compare Source

v9.11.0

Compare Source


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • ""
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the dependencies Pull requests that update a dependency file label Nov 18, 2024
@renovate renovate Bot force-pushed the renovate/npm-firebase-vulnerability branch from 1d2a904 to ca1db77 Compare June 18, 2025 01:01
@renovate renovate Bot force-pushed the renovate/npm-firebase-vulnerability branch from ca1db77 to 5658603 Compare August 10, 2025 14:58
@renovate renovate Bot force-pushed the renovate/npm-firebase-vulnerability branch from 5658603 to 14c2e96 Compare August 19, 2025 14:03
@renovate renovate Bot force-pushed the renovate/npm-firebase-vulnerability branch from 14c2e96 to 6ece675 Compare December 3, 2025 14:39
@renovate renovate Bot force-pushed the renovate/npm-firebase-vulnerability branch 2 times, most recently from 474249d to 1e42e6c Compare March 20, 2026 01:21
@renovate renovate Bot changed the title fix(deps): update dependency firebase to v10 [security] fix(deps): update dependency firebase to v10 [security] - autoclosed Mar 27, 2026
@renovate renovate Bot closed this Mar 27, 2026
@renovate renovate Bot deleted the renovate/npm-firebase-vulnerability branch March 27, 2026 01:26
@renovate renovate Bot changed the title fix(deps): update dependency firebase to v10 [security] - autoclosed fix(deps): update dependency firebase to v10 [security] Mar 30, 2026
@renovate renovate Bot reopened this Mar 30, 2026
@renovate renovate Bot force-pushed the renovate/npm-firebase-vulnerability branch 2 times, most recently from 1e42e6c to 5ed0aac Compare March 30, 2026 21:13
@renovate renovate Bot changed the title fix(deps): update dependency firebase to v10 [security] Update dependency firebase to v10 [SECURITY] Apr 8, 2026
@renovate renovate Bot force-pushed the renovate/npm-firebase-vulnerability branch from 5ed0aac to 6f5c633 Compare April 8, 2026 14:58
@renovate renovate Bot changed the title Update dependency firebase to v10 [SECURITY] Update dependency firebase to v10 [SECURITY] - abandoned Apr 27, 2026
@renovate
Copy link
Copy Markdown
Contributor Author

renovate Bot commented Apr 27, 2026

Autoclosing Skipped

This PR has been flagged for autoclosing. However, it is being skipped due to the branch being already modified. Please close/delete it manually or report a bug if you think this is in error.

@renovate renovate Bot changed the title Update dependency firebase to v10 [SECURITY] - abandoned Update dependency firebase to v10 [SECURITY] Apr 27, 2026
@renovate renovate Bot force-pushed the renovate/npm-firebase-vulnerability branch from 6f5c633 to 7e52e4c Compare April 29, 2026 11:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants