<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Do we need to worry about vulnerabilities?]]></title><description><![CDATA[<p dir="auto">Having refreshed my build recently, I’ve noticed a number of modules flagging node modules as vulnerable, many high.</p>
<p dir="auto">Is this something realistically we need to be concerned about?</p>
]]></description><link>https://forum.magicmirror.builders/topic/18413/do-we-need-to-worry-about-vulnerabilities</link><generator>RSS for Node</generator><lastBuildDate>Sun, 12 Jul 2026 09:11:01 GMT</lastBuildDate><atom:link href="https://forum.magicmirror.builders/topic/18413.rss" rel="self" type="application/rss+xml"/><pubDate>Thu, 18 Jan 2024 12:06:53 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Do we need to worry about vulnerabilities? on Thu, 18 Jan 2024 17:05:38 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/mumblebaj" aria-label="Profile: mumblebaj">@<bdi>mumblebaj</bdi></a> again this is possible IF the one of these systems is ON the internet…  but typically this is  pc on same house network as pi…</p>
<p dir="auto">and 192.168 , 172 and 10. networks are not routable over the internet, so your device would have to have a ip address on the other side of the ISP router…  or and open port (port forwarding)</p>
<p dir="auto">if you need remote ssh use the stuff  I started posting about here<br />
<a href="https://forum.magicmirror.builders/post/114693">https://forum.magicmirror.builders/post/114693</a><br />
I will never have another port forwarded port</p>
]]></description><link>https://forum.magicmirror.builders/post/114707</link><guid isPermaLink="true">https://forum.magicmirror.builders/post/114707</guid><dc:creator><![CDATA[sdetweil]]></dc:creator><pubDate>Thu, 18 Jan 2024 17:05:38 GMT</pubDate></item><item><title><![CDATA[Reply to Do we need to worry about vulnerabilities? on Thu, 18 Jan 2024 16:37:47 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/sdetweil" aria-label="Profile: sdetweil">@<bdi>sdetweil</bdi></a> There is a new SSH security vulnerability identified in December. CVE-2023-48795. Any chances this would be a problem to this project in anyway? I do know that it requires an active MITM (Man in the middle). Short description below.</p>
<p dir="auto">SSH vulnerability exploitable in Terrapin attacks (CVE-2023-48795) Security researchers have discovered a vulnerability (CVE-2023-48795) in the SSH cryptographic network protocol that could allow an attacker to downgrade the connection’s security by truncating the extension negotiation message.</p>
]]></description><link>https://forum.magicmirror.builders/post/114706</link><guid isPermaLink="true">https://forum.magicmirror.builders/post/114706</guid><dc:creator><![CDATA[mumblebaj]]></dc:creator><pubDate>Thu, 18 Jan 2024 16:37:47 GMT</pubDate></item><item><title><![CDATA[Reply to Do we need to worry about vulnerabilities? on Thu, 18 Jan 2024 13:24:34 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/funkoid" aria-label="Profile: funkoid">@<bdi>funkoid</bdi></a> generally no. if this was a public website with lots of users concurrently maybe.</p>
]]></description><link>https://forum.magicmirror.builders/post/114703</link><guid isPermaLink="true">https://forum.magicmirror.builders/post/114703</guid><dc:creator><![CDATA[sdetweil]]></dc:creator><pubDate>Thu, 18 Jan 2024 13:24:34 GMT</pubDate></item></channel></rss>