<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Luxon Inefficient Regular Expression Complexity vulnerability in ArcGIS REST APIs and Services Questions</title>
    <link>https://community.esri.com/t5/arcgis-rest-apis-and-services-questions/luxon-inefficient-regular-expression-complexity/m-p/1252453#M4361</link>
    <description>&lt;P&gt;Any traction on this from esri yet?&lt;/P&gt;</description>
    <pubDate>Fri, 27 Jan 2023 18:23:03 GMT</pubDate>
    <dc:creator>René_Ténière</dc:creator>
    <dc:date>2023-01-27T18:23:03Z</dc:date>
    <item>
      <title>Luxon Inefficient Regular Expression Complexity vulnerability</title>
      <link>https://community.esri.com/t5/arcgis-rest-apis-and-services-questions/luxon-inefficient-regular-expression-complexity/m-p/1249329#M4347</link>
      <description>&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;I'm getting an error&amp;nbsp; today in my pipeline that runs npm audit -prod&lt;/P&gt;&lt;P&gt;luxon 2.0.0 - 2.5.1&lt;BR /&gt;Severity: high&lt;BR /&gt;Luxon Inefficient Regular Expression Complexity vulnerability - &lt;A href="https://github.com/advisories/GHSA-3xq5-wjfh-ppjc" target="_blank" rel="noopener"&gt;https://github.com/advisories/GHSA-3xq5-wjfh-ppjc&lt;/A&gt;&lt;BR /&gt;fix available via `npm audit fix --force`&lt;BR /&gt;Will install &lt;a href="https://community.esri.com/t5/user/viewprofilepage/user-id/642472"&gt;@ArcGIS&lt;/a&gt;/core@4.25.5, which is outside the stated dependency range&lt;BR /&gt;node_modules/luxon&lt;BR /&gt;&lt;a href="https://community.esri.com/t5/user/viewprofilepage/user-id/642472"&gt;@ArcGIS&lt;/a&gt;/core 4.21.0-next.20210721 - 4.25.0-next.20221108&lt;BR /&gt;Depends on vulnerable versions of luxon&lt;BR /&gt;node_modules/@arcgis/core&lt;/P&gt;&lt;P&gt;All version of ArcGis are using luxon versions that have this vulnerability. In git hub for luxon it says to update to newer versions&lt;/P&gt;&lt;P&gt;&lt;A href="https://github.com/advisories/GHSA-3xq5-wjfh-ppjc" target="_blank" rel="noopener"&gt;https://github.com/advisories/GHSA-3xq5-wjfh-ppjc&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Is ArcGis going to release an update soon? if not i cannot release my app since i'm not allowed to deploy high severity vulnerabilities.&lt;BR /&gt;Is there a work around while you work on an upgrade?&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;Fabian&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jan 2023 00:37:09 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-rest-apis-and-services-questions/luxon-inefficient-regular-expression-complexity/m-p/1249329#M4347</guid>
      <dc:creator>FabianHanggi</dc:creator>
      <dc:date>2023-01-19T00:37:09Z</dc:date>
    </item>
    <item>
      <title>Re: Luxon Inefficient Regular Expression Complexity vulnerability</title>
      <link>https://community.esri.com/t5/arcgis-rest-apis-and-services-questions/luxon-inefficient-regular-expression-complexity/m-p/1249718#M4348</link>
      <description>&lt;P&gt;Also encountering this issue&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jan 2023 21:45:07 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-rest-apis-and-services-questions/luxon-inefficient-regular-expression-complexity/m-p/1249718#M4348</guid>
      <dc:creator>Stacy-Rendall</dc:creator>
      <dc:date>2023-01-19T21:45:07Z</dc:date>
    </item>
    <item>
      <title>Re: Luxon Inefficient Regular Expression Complexity vulnerability</title>
      <link>https://community.esri.com/t5/arcgis-rest-apis-and-services-questions/luxon-inefficient-regular-expression-complexity/m-p/1252381#M4360</link>
      <description>&lt;P&gt;Same issue here.&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jan 2023 15:50:10 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-rest-apis-and-services-questions/luxon-inefficient-regular-expression-complexity/m-p/1252381#M4360</guid>
      <dc:creator>Anonymous User</dc:creator>
      <dc:date>2023-01-27T15:50:10Z</dc:date>
    </item>
    <item>
      <title>Re: Luxon Inefficient Regular Expression Complexity vulnerability</title>
      <link>https://community.esri.com/t5/arcgis-rest-apis-and-services-questions/luxon-inefficient-regular-expression-complexity/m-p/1252453#M4361</link>
      <description>&lt;P&gt;Any traction on this from esri yet?&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jan 2023 18:23:03 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-rest-apis-and-services-questions/luxon-inefficient-regular-expression-complexity/m-p/1252453#M4361</guid>
      <dc:creator>René_Ténière</dc:creator>
      <dc:date>2023-01-27T18:23:03Z</dc:date>
    </item>
    <item>
      <title>Re: Luxon Inefficient Regular Expression Complexity vulnerability</title>
      <link>https://community.esri.com/t5/arcgis-rest-apis-and-services-questions/luxon-inefficient-regular-expression-complexity/m-p/1252585#M4362</link>
      <description>&lt;P&gt;Response from ESRI support&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hello Fabian,&lt;BR /&gt;&lt;BR /&gt;I did receive a response from Esri inc. and this issue&amp;nbsp;has already been resolved in the next release. When the next release comes out you will just need to upgrade. The next release has been updated to 3.2.1.&lt;BR /&gt;&lt;BR /&gt;The next release of the JavaScript SDK is scheduled for late February or early march of 2023.&lt;BR /&gt;&lt;BR /&gt;Let me know if you have any further questions.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Thank you,&lt;BR /&gt;Victor C.&lt;BR /&gt;Esri Canada&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jan 2023 23:59:38 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-rest-apis-and-services-questions/luxon-inefficient-regular-expression-complexity/m-p/1252585#M4362</guid>
      <dc:creator>FabianHanggi</dc:creator>
      <dc:date>2023-01-27T23:59:38Z</dc:date>
    </item>
    <item>
      <title>Re: Luxon Inefficient Regular Expression Complexity vulnerability</title>
      <link>https://community.esri.com/t5/arcgis-rest-apis-and-services-questions/luxon-inefficient-regular-expression-complexity/m-p/1253581#M4367</link>
      <description>&lt;P&gt;4.26&amp;nbsp;does not depend on version(s) of the Luxon module affected by CVE-2023-22467.&lt;BR /&gt;&lt;BR /&gt;You can validate this by installing the 4.26 release using the following command:&lt;/P&gt;&lt;P&gt;&amp;nbsp;npm install &lt;a href="https://community.esri.com/t5/user/viewprofilepage/user-id/642472"&gt;@ArcGIS&lt;/a&gt;/core@next&lt;/P&gt;</description>
      <pubDate>Tue, 31 Jan 2023 22:18:32 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-rest-apis-and-services-questions/luxon-inefficient-regular-expression-complexity/m-p/1253581#M4367</guid>
      <dc:creator>Anonymous User</dc:creator>
      <dc:date>2023-01-31T22:18:32Z</dc:date>
    </item>
    <item>
      <title>Re: Luxon Inefficient Regular Expression Complexity vulnerability</title>
      <link>https://community.esri.com/t5/arcgis-rest-apis-and-services-questions/luxon-inefficient-regular-expression-complexity/m-p/1253810#M4370</link>
      <description>&lt;P&gt;I am still in development so I will wait for the official release.&lt;/P&gt;</description>
      <pubDate>Wed, 01 Feb 2023 14:19:30 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-rest-apis-and-services-questions/luxon-inefficient-regular-expression-complexity/m-p/1253810#M4370</guid>
      <dc:creator>René_Ténière</dc:creator>
      <dc:date>2023-02-01T14:19:30Z</dc:date>
    </item>
    <item>
      <title>Re: Luxon Inefficient Regular Expression Complexity vulnerability</title>
      <link>https://community.esri.com/t5/arcgis-rest-apis-and-services-questions/luxon-inefficient-regular-expression-complexity/m-p/1267817#M4407</link>
      <description>&lt;P&gt;Just installed 4.26.5. This issue has been resolved&lt;/P&gt;</description>
      <pubDate>Tue, 14 Mar 2023 22:09:38 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-rest-apis-and-services-questions/luxon-inefficient-regular-expression-complexity/m-p/1267817#M4407</guid>
      <dc:creator>FabianHanggi</dc:creator>
      <dc:date>2023-03-14T22:09:38Z</dc:date>
    </item>
  </channel>
</rss>

