Skip to content

fix(deps): Update dependency firebase to v10 [SECURITY]#412

Open
renovate[bot] wants to merge 1 commit into
masterfrom
renovate/npm-firebase-vulnerability
Open

fix(deps): Update dependency firebase to v10 [SECURITY]#412
renovate[bot] wants to merge 1 commit into
masterfrom
renovate/npm-firebase-vulnerability

Conversation

@renovate

@renovate renovate Bot commented Nov 18, 2024

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
firebase (source, changelog) ^7.24.0^10.0.0 age confidence

Firebase JavaScript SDK allows attackers to manipulate the "_authTokenSyncURL" to point to their own server

CVE-2024-11023 / GHSA-3wf4-68gx-mph8

More information

Details

Firebase JavaScript SDK utilizes a "FIREBASE_DEFAULTS" cookie to store configuration data, including an "_authTokenSyncURL" field used for session synchronization. If this cookie field is preset via an attacker by any other method, the attacker can manipulate the "_authTokenSyncURL" to point to their own server and it would allow am actor to capture user session data transmitted by the SDK. We recommend upgrading Firebase JS SDK at least to 10.9.0.

Severity

  • CVSS Score: 5.2 / 10 (Medium)
  • Vector String: CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:A/VC:L/VI:L/VA:L/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

firebase/firebase-js-sdk (firebase)

v10.9.0

Compare Source

v10.8.1

Compare Source

v10.8.0

Compare Source

v10.7.2

Compare Source

v10.7.1

Compare Source

v10.7.0

Compare Source

v10.6.0

Compare Source

v10.5.2

Compare Source

v10.5.1

Compare Source

v10.5.0

Compare Source

v10.4.0

Compare Source

v10.3.1

Compare Source

v10.3.0

Compare Source

v10.2.0

Compare Source

v10.1.0

Compare Source

v10.0.0

Compare Source

v9.23.0

Compare Source

v9.22.2

Compare Source

v9.22.1

Compare Source

v9.22.0

Compare Source

v9.21.0

Compare Source

v9.20.0

Compare Source

v9.19.1

Compare Source

v9.19.0

Compare Source

v9.18.0

Compare Source

v9.17.2

Compare Source

v9.17.1

Compare Source

v9.17.0

Compare Source

v9.16.0

Compare Source

v9.15.0

Compare Source

v9.14.0

Compare Source

v9.13.0

Compare Source

v9.12.1

Compare Source

v9.12.0

Compare Source

v9.11.0

Compare Source

v9.10.0

Compare Source

v9.9.4

Compare Source

v9.9.3

Compare Source

v9.9.0

Compare Source

v9.8.4

Compare Source

v9.8.3

Compare Source

v9.8.2

Compare Source

v9.8.1

Compare Source

v9.8.0

Compare Source

v9.7.0

Compare Source

v9.6.11

Compare Source

v9.6.10

Compare Source

v9.6.9

Compare Source

v9.6.8

Compare Source

v9.6.7

Compare Source

v9.6.6

Compare Source

v9.6.5

Compare Source

v9.6.4

Compare Source

v9.6.3

Compare Source

v9.6.2

Compare Source

v9.6.1

Compare Source

v9.6.0

Compare Source

v9.5.0

Compare Source

v9.4.1

Compare Source

v9.4.0

Compare Source

v9.3.0

Compare Source

v9.2.0

Compare Source

v9.1.3

Compare Source

v9.1.2

Compare Source

v9.1.1

Compare Source

v9.1.0

Compare Source

v9.0.2

Compare Source

v9.0.1

Compare Source

v9.0.0

Compare Source

v8.10.1

Compare Source

v8.10.0

Compare Source

v8.9.1

Compare Source

v8.9.0

Compare Source

v8.8.1

Compare Source

v8.8.0

Compare Source

v8.7.1

Compare Source

v8.7.0

Compare Source

v8.6.8

Compare Source

v8.6.7

Compare Source

v8.6.6

Compare Source

v8.6.5

Compare Source

v8.6.4

Compare Source

v8.6.3

Compare Source

v8.6.2

Compare Source

v8.6.1

Compare Source

v8.6.0

Compare Source

v8.5.0

Compare Source

v8.4.3

Compare Source

v8.4.2

Compare Source

v8.4.1

Compare Source

v8.4.0

Compare Source

v8.3.3

Compare Source

v8.3.2

Compare Source

v8.3.1

Compare Source

v8.3.0

Compare Source

v8.2.10

Compare Source

v8.2.9

Compare Source

v8.2.8

Compare Source

v8.2.7

Compare Source

v8.2.6

Compare Source

v8.2.5

Compare Source

v8.2.4

Compare Source

v8.1.2

Compare Source

v8.1.1

Compare Source

v8.1.0

Compare Source

v8.0.2

Compare Source

v8.0.1

Compare Source

v8.0.0

Compare Source


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate using a curated preset maintained by Sanity. View repository job log here

@vercel

vercel Bot commented Nov 18, 2024

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
hyperfokus Error Error Jun 13, 2026 8:00pm

@socket-security

socket-security Bot commented Nov 18, 2024

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedfirebase@​7.24.0 ⏵ 10.14.180 +1100 +2100 +198100

View full report

@renovate renovate Bot force-pushed the renovate/npm-firebase-vulnerability branch from 1c587a2 to 1456b9d Compare August 10, 2025 14:25
@renovate renovate Bot force-pushed the renovate/npm-firebase-vulnerability branch from 1456b9d to 4e82dce Compare August 19, 2025 18:09
@socket-security

socket-security Bot commented Aug 19, 2025

Copy link
Copy Markdown

All alerts resolved. Learn more about Socket for GitHub.

This PR previously contained dependency changes with security issues that have been resolved, removed, or ignored.

View full report

@renovate renovate Bot changed the title fix(deps): Update dependency firebase to v10 [SECURITY] fix(deps): Update dependency firebase to v10 [SECURITY] - autoclosed Mar 27, 2026
@renovate renovate Bot closed this Mar 27, 2026
@renovate renovate Bot deleted the renovate/npm-firebase-vulnerability branch March 27, 2026 01:41
@renovate renovate Bot changed the title fix(deps): Update dependency firebase to v10 [SECURITY] - autoclosed fix(deps): Update dependency firebase to v10 [SECURITY] Mar 30, 2026
@renovate renovate Bot reopened this Mar 30, 2026
@renovate renovate Bot force-pushed the renovate/npm-firebase-vulnerability branch 2 times, most recently from 4e82dce to fa29cf5 Compare March 30, 2026 22:18
@renovate renovate Bot changed the title fix(deps): Update dependency firebase to v10 [SECURITY] fix(deps): Update dependency firebase to v10 [SECURITY] - autoclosed Apr 27, 2026
@renovate renovate Bot closed this Apr 27, 2026
@renovate renovate Bot changed the title fix(deps): Update dependency firebase to v10 [SECURITY] - autoclosed fix(deps): Update dependency firebase to v10 [SECURITY] Apr 27, 2026
@renovate renovate Bot reopened this Apr 27, 2026
@renovate renovate Bot force-pushed the renovate/npm-firebase-vulnerability branch 2 times, most recently from fa29cf5 to 9a46e70 Compare April 27, 2026 19:30
@renovate renovate Bot force-pushed the renovate/npm-firebase-vulnerability branch from 9a46e70 to cbafa56 Compare April 29, 2026 14:11
@renovate renovate Bot force-pushed the renovate/npm-firebase-vulnerability branch from cbafa56 to 79c4fcc Compare May 12, 2026 11:01
@renovate renovate Bot force-pushed the renovate/npm-firebase-vulnerability branch from 79c4fcc to c0e6754 Compare May 18, 2026 10:59
@renovate renovate Bot force-pushed the renovate/npm-firebase-vulnerability branch from c0e6754 to 4da4e0e Compare May 28, 2026 13:54
@renovate renovate Bot force-pushed the renovate/npm-firebase-vulnerability branch from 4da4e0e to 7d545fa Compare June 1, 2026 19:47
@renovate renovate Bot force-pushed the renovate/npm-firebase-vulnerability branch from 7d545fa to 610c106 Compare June 13, 2026 20:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants