Version 2.3.10 Is Not Older Than 2.3.9 — JavaScript Bug Hunt

Modelled on the Equifax breach (2017), which turned on a known-vulnerable dependency that was never upgraded.

  • Language: JavaScript
  • Layer: Backend
  • Difficulty: Medium
  • Concepts: Security, Versioning
  • Modelled on: Equifax · 2017
  • Visible tests: an older patch is vulnerable; a double-digit patch is not older; a double-digit major is not older
  • Reward: 50 XP for a complete fix

Briefing

Modelled on the Equifax breach (2017), which turned on a known-vulnerable dependency that was never upgraded. A common contributing bug in patch tooling is comparing semantic versions as strings, so "2.3.10" sorts before "2.3.9" and a patched build is reported as still vulnerable — or worse, an unpatched one as fixed.

versions.js compares versions lexicographically.

Fix isVulnerable so versions are compared numerically, component by component.

Bug report

BUG-CVE2017-5638 · Priority: Critical · Reported by: security

isVulnerable(installed, fixedIn) must return true when the installed version is strictly OLDER than fixedIn, comparing "major.minor.patch" numerically.

Observed: string comparison decides that "2.3.10" < "2.3.9", so a fully patched host is flagged, and "10.0.0" < "9.0.0" leaves a truly vulnerable host unflagged.

Logs

[scan] host web-14 installed=2.3.10 fixedIn=2.3.9 vulnerable=true (wrong)
[scan] host web-22 installed=10.0.0 fixedIn=9.0.0 vulnerable=false (wrong)

The code as shipped

src/scan/versions.js (editable)

// True when the installed version predates the fix.
exports.isVulnerable = function (installed, fixedIn) {
  return installed < fixedIn;
};

Read-only context: src/scan/SEMVER.js.

Open the hunt to edit the files, run the visible tests and submit against the hidden ones. More JavaScript bug hunts.