npm install出现多种漏洞如何解决?附firebase漏洞详情
解决npm audit检测到的firebase资源消耗漏洞
你遇到的是Uncontrolled Resource Consumption类型的firebase相关漏洞,根源是项目中fcm-node(>=1.4.0)或fcm-notification依赖的旧版firebase-admin(4.0.0-11.4.0),这些旧版admin包又嵌套依赖了存在问题的@firebase/util、@firebase/app等子包。
漏洞检测日志:
Uncontrolled Resource Consumption in firebase fix available via `npm audit fix --force` Will install fcm-node@1.3.0, which is a breaking change node_modules/fcm-notification/node_modules/@firebase/util @firebase/app <=0.6.13-longpoll.66863f547 || 0.6.14-2021026232412 - 0.6.14-canary.fd16bb26d || 0.6.15-2021119233939 - 0.6.15-eap-storage-emulator.ed256f582 Depends on vulnerable versions of @firebase/util node_modules/fcm-notification/node_modules/@firebase/app firebase-admin 4.0.0 - 11.4.0 Depends on vulnerable versions of @firebase/app Depends on vulnerable versions of @firebase/database Depends on vulnerable versions of @google-cloud/firestore Depends on vulnerable versions of dicer Depends on vulnerable versions of jsonwebtoken Depends on vulnerable versions of node-forge node_modules/fcm-node/node_modules/firebase-admin node_modules/fcm-notification/node_modules/firebase-admin fcm-node >=1.4.0 Depends on vulnerable versions of firebase-admin node_modules/fcm-node fcm-notification * Depends on vulnerable versions of firebase-admin node_modules/fcm-notification @firebase/database <=0.7.1-canary.fc9de467b || 0.8.0-202010180421 - 0.8.0-canary.bab4e1935 || 0.8.1-1.0.0-eap-firestore-debug.9c6096f43 - 0.8.1-canary.ff9dc3460 || 0.8.2-20210721223 - 0.8.2-longpoll.66863f547 || 0.8.3-2021012224526 - 0.8.3-canary.fb90580e5 || 0.9.0-2021019222814 - 0.9.0-canary.d9b945fed || 0.9.1-2021026232412 - 0.9.1-canary.fd16bb26d || 0.9.2-202112213818 - 0.9.2-canary.f5139220e || 0.9.3-202119234540 - 0.9.3-canary.ee6980dee || 0.9.4-2021119233939 - 0.9.4-eap-storage-emulator.ed256f582 Depends on vulnerable versions of @firebase/util node_modules/fcm-notification/node_modules/@firebase/database
可行解决方案
1. 尝试官方强制修复(注意破坏性变更)
运行官方提示的命令,这会将fcm-node降级到1.3.0以修复漏洞,但可能破坏现有代码逻辑:
npm audit fix --force
重点提醒:执行前务必核对fcm-node 1.3.0的API文档,确认项目中的推送逻辑兼容旧版本。
2. 手动升级依赖(推荐,避免降级)
如果不想降级fcm-node,可以直接升级相关依赖:
- 若项目
package.json直接声明了fcm-node或fcm-notification,将版本号改为最新稳定版,然后执行:
npm install
- 若为间接依赖(项目未直接声明),使用npm的
overrides功能(需npm 8.3+)强制指定安全版本的firebase-admin:
在package.json中添加:
"overrides": { "firebase-admin": "^11.5.0" }
随后清理旧依赖并重装:
rm -rf node_modules package-lock.json npm install
3. 清理缓存重新验证
若以上步骤无效,清理npm缓存并重装依赖:
npm cache clean --force rm -rf node_modules package-lock.json npm install
4. 验证修复
执行以下命令确认漏洞已解决:
npm audit
内容的提问来源于stack exchange,提问作者Robert Melente
相关产品推荐
相关产品推荐

