Version 2.3.10 Is Not Older Than 2.3.9 — JavaScript Bug Hunt
Modelled on the Equifax breach (2017), which turned on a known-vulnerable dependency that was never upgraded.
- Language: JavaScript
- Layer: Backend
- Difficulty: Medium
- Concepts: Security, Versioning
- Modelled on: Equifax · 2017
- Visible tests: an older patch is vulnerable; a double-digit patch is not older; a double-digit major is not older
- Reward: 50 XP for a complete fix
Briefing
Modelled on the Equifax breach (2017), which turned on a known-vulnerable dependency that was never upgraded. A common contributing bug in patch tooling is comparing semantic versions as strings, so "2.3.10" sorts before "2.3.9" and a patched build is reported as still vulnerable — or worse, an unpatched one as fixed.
versions.js compares versions lexicographically.
Fix isVulnerable so versions are compared numerically, component by component.
Bug report
BUG-CVE2017-5638 · Priority: Critical · Reported by: security
isVulnerable(installed, fixedIn) must return true when the installed version is strictly OLDER than fixedIn, comparing "major.minor.patch" numerically.
Observed: string comparison decides that "2.3.10" < "2.3.9", so a fully patched host is flagged, and "10.0.0" < "9.0.0" leaves a truly vulnerable host unflagged.
Logs
[scan] host web-14 installed=2.3.10 fixedIn=2.3.9 vulnerable=true (wrong)
[scan] host web-22 installed=10.0.0 fixedIn=9.0.0 vulnerable=false (wrong)The code as shipped
src/scan/versions.js (editable)
// True when the installed version predates the fix.
exports.isVulnerable = function (installed, fixedIn) {
return installed < fixedIn;
};
Read-only context: src/scan/SEMVER.js.
Open the hunt to edit the files, run the visible tests and submit against the hidden ones. More JavaScript bug hunts.