Skip to content

fix(deps): update dependency firebase to v10 [security]#412

Open
renovate[bot] wants to merge 1 commit into
masterfrom
renovate/npm-firebase-vulnerability
Open

fix(deps): update dependency firebase to v10 [security]#412
renovate[bot] wants to merge 1 commit into
masterfrom
renovate/npm-firebase-vulnerability

Conversation

@renovate

@renovate renovate Bot commented Nov 18, 2024

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
firebase (source, changelog) ^7.24.0^10.0.0 age confidence

Firebase JavaScript SDK allows attackers to manipulate the "_authTokenSyncURL" to point to their own server

CVE-2024-11023 / GHSA-3wf4-68gx-mph8

More information

Details

Firebase JavaScript SDK utilizes a "FIREBASE_DEFAULTS" cookie to store configuration data, including an "_authTokenSyncURL" field used for session synchronization. If this cookie field is preset via an attacker by any other method, the attacker can manipulate the "_authTokenSyncURL" to point to their own server and it would allow am actor to capture user session data transmitted by the SDK. We recommend upgrading Firebase JS SDK at least to 10.9.0.

Severity

  • CVSS Score: 5.2 / 10 (Medium)
  • Vector String: CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:A/VC:L/VI:L/VA:L/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

firebase/firebase-js-sdk (firebase)

v10.9.0

Compare Source

v10.8.1

Compare Source

v10.8.0

Compare Source

v10.7.2

Compare Source

v10.7.1

Compare Source

v10.7.0

Compare Source

v10.6.0

Compare Source

v10.5.2

Compare Source

v10.5.1

Compare Source

v10.5.0

Compare Source

v10.4.0

Compare Source

v10.3.1

Compare Source

v10.3.0

Compare Source

v10.2.0

Compare Source

v10.1.0

Compare Source

v10.0.0

Compare Source

v9.23.0

Compare Source

v9.22.2

Compare Source

v9.22.1

Compare Source

v9.22.0

Compare Source

v9.21.0

Compare Source

v9.20.0

Compare Source

v9.19.1

Compare Source

v9.19.0

Compare Source

v9.18.0

Compare Source

v9.17.2

Compare Source

v9.17.1

Compare Source

v9.17.0

Compare Source

v9.16.0

Compare Source

v9.15.0

Compare Source

v9.14.0

Compare Source

v9.13.0

Compare Source

v9.12.1

Compare Source

v9.12.0

Compare Source

v9.11.0

Compare Source

v9.10.0

Compare Source

v9.9.4

Compare Source

v9.9.3

Compare Source

v9.9.0

Compare Source

v9.8.4

Compare Source

v9.8.3

Compare Source

v9.8.2

Compare Source

v9.8.1

Compare Source

v9.8.0

Compare Source

v9.7.0

Compare Source

v9.6.11

Compare Source

v9.6.10

Compare Source

v9.6.9

Compare Source

v9.6.8

Compare Source

v9.6.7

Compare Source

v9.6.6

Compare Source

v9.6.5

Compare Source

v9.6.4

Compare Source

v9.6.3

Compare Source

v9.6.2

Compare Source

v9.6.1

Compare Source

v9.6.0

Compare Source

v9.5.0

Compare Source

v9.4.1

Compare Source

v9.4.0

Compare Source

v9.3.0

Compare Source

v9.2.0

Compare Source

v9.1.3

Compare Source

v9.1.2

Compare Source

v9.1.1

Compare Source

v9.1.0

Compare Source

v9.0.2

Compare Source

v9.0.1

Compare Source

v9.0.0

Compare Source

v8.10.1

Compare Source

v8.10.0

Compare Source

v8.9.1

Compare Source

v8.9.0

Compare Source

v8.8.1

Compare Source

v8.8.0

Compare Source

v8.7.1

Compare Source

v8.7.0

Compare Source

v8.6.8

Compare Source

v8.6.7

Compare Source

v8.6.6

Compare Source

v8.6.5

Compare Source

v8.6.4

Compare Source

v8.6.3

Compare Source

v8.6.2

Compare Source

v8.6.1

Compare Source

v8.6.0

Compare Source

v8.5.0

Compare Source

v8.4.3

Compare Source

v8.4.2

Compare Source

v8.4.1

Compare Source

v8.4.0

Compare Source

v8.3.3

Compare Source

v8.3.2

Compare Source

v8.3.1

Compare Source

v8.3.0

Compare Source

v8.2.10

Compare Source

v8.2.9

Compare Source

v8.2.8

Compare Source

v8.2.7

Compare Source

v8.2.6

Compare Source

v8.2.5

Compare Source

v8.2.4

Compare Source

v8.1.2

Compare Source

v8.1.1

Compare Source

v8.1.0

Compare Source

v8.0.2

Compare Source

v8.0.1

Compare Source

v8.0.0

Compare Source


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate using a curated preset maintained by Sanity. View repository job log here

@vercel

vercel Bot commented Nov 18, 2024

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
hyperfokus Error Error Jul 12, 2026 1:16pm

@socket-security

socket-security Bot commented Nov 18, 2024

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedfirebase@​7.24.0 ⏵ 10.14.180 +1100 +2100 +198100

View full report

@renovate
renovate Bot force-pushed the renovate/npm-firebase-vulnerability branch from 1c587a2 to 1456b9d Compare August 10, 2025 14:25
@renovate
renovate Bot force-pushed the renovate/npm-firebase-vulnerability branch from 1456b9d to 4e82dce Compare August 19, 2025 18:09
@socket-security

socket-security Bot commented Aug 19, 2025

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn High
Obfuscated code: npm yargs is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: ?npm/firebase@10.14.1npm/yargs@17.7.3

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore npm/yargs@17.7.3. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@renovate renovate Bot changed the title fix(deps): Update dependency firebase to v10 [SECURITY] fix(deps): Update dependency firebase to v10 [SECURITY] - autoclosed Mar 27, 2026
@renovate renovate Bot closed this Mar 27, 2026
@renovate
renovate Bot deleted the renovate/npm-firebase-vulnerability branch March 27, 2026 01:41
@renovate renovate Bot changed the title fix(deps): Update dependency firebase to v10 [SECURITY] - autoclosed fix(deps): Update dependency firebase to v10 [SECURITY] Mar 30, 2026
@renovate renovate Bot reopened this Mar 30, 2026
@renovate
renovate Bot force-pushed the renovate/npm-firebase-vulnerability branch 2 times, most recently from 4e82dce to fa29cf5 Compare March 30, 2026 22:18
@renovate renovate Bot changed the title fix(deps): Update dependency firebase to v10 [SECURITY] fix(deps): Update dependency firebase to v10 [SECURITY] - autoclosed Apr 27, 2026
@renovate renovate Bot closed this Apr 27, 2026
@renovate renovate Bot changed the title fix(deps): Update dependency firebase to v10 [SECURITY] - autoclosed fix(deps): Update dependency firebase to v10 [SECURITY] Apr 27, 2026
@renovate renovate Bot reopened this Apr 27, 2026
@renovate
renovate Bot force-pushed the renovate/npm-firebase-vulnerability branch 2 times, most recently from fa29cf5 to 9a46e70 Compare April 27, 2026 19:30
@renovate
renovate Bot force-pushed the renovate/npm-firebase-vulnerability branch from 9a46e70 to cbafa56 Compare April 29, 2026 14:11
@renovate
renovate Bot force-pushed the renovate/npm-firebase-vulnerability branch from cbafa56 to 79c4fcc Compare May 12, 2026 11:01
@renovate
renovate Bot force-pushed the renovate/npm-firebase-vulnerability branch from 79c4fcc to c0e6754 Compare May 18, 2026 10:59
@renovate
renovate Bot force-pushed the renovate/npm-firebase-vulnerability branch from c0e6754 to 4da4e0e Compare May 28, 2026 13:54
@renovate
renovate Bot force-pushed the renovate/npm-firebase-vulnerability branch from 4da4e0e to 7d545fa Compare June 1, 2026 19:47
@renovate
renovate Bot force-pushed the renovate/npm-firebase-vulnerability branch from 7d545fa to 610c106 Compare June 13, 2026 20:00
@renovate renovate Bot changed the title fix(deps): Update dependency firebase to v10 [SECURITY] fix(deps): update dependency firebase to v10 [security] Jun 22, 2026
@renovate
renovate Bot force-pushed the renovate/npm-firebase-vulnerability branch from 610c106 to f1774ff Compare July 12, 2026 13:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants