Jump to content
TNG Community

[Security Alert] The Open Street Maps (OSM) Add-On appears to have polyfill.io exploit vulnerability


justinhow

Recommended Posts

The OSM add-on adds this "https://cdn.polyfill.io/v2/polyfill.min.js" to a number of TNG php files and it also appears in heatmap_OSM.php. This includes the latest version Openstreetmap_v14.0.5.9.zip.

This would appear to make it vulnerable to the Polyfill exploit (https://dev.to/snyk/polyfill-supply-chain-attack-embeds-malware-in-javascript-cdn-assets-55d6)

Cloudflare have a blog post about how to remove the vulnerability here https://blog.cloudflare.com/polyfill-io-now-available-on-cdnjs-reduce-your-supply-chain-risk 

I edited my own copies of the OSM .cfg and heatmap_OSM.php files to make the required change as described in the blog.

I would suggest the folks who look after this add-on have a look at this issue (I realise the original developer no longer manages it) ASAP.

Link to comment
Share on other sites

  • justinhow changed the title to [Security Alert] The Open Street Maps (OSM) Add-On appears to have polyfill.io exploit vulnerability
9 hours ago, justinhow said:

I would suggest the folks who look after this add-on

Have sent you a PM.

Ron

Link to comment
Share on other sites

On 6/29/2024 at 10:14 AM, justinhow said:

The OSM add-on adds this "https://cdn.polyfill.io/v2/polyfill.min.js" to a number of TNG php files and it also appears in heatmap_OSM.php. This includes the latest version Openstreetmap_v14.0.5.9.zip.

I reworked the OpenStreetMap mod for TNG 14.0.5 only because Michel was not available.

Ron sent me a reworked version of the mod but I have not posted it because I do not have the time to test and am wondering whether the whole polyfill javascript could not simply be removed.

I do not have the time to test any of this and only use the OpenStreetMap to ensure that both the Google Maps and OpenStreetMap work for the Ancestor Map 

Dealing with more important life issues

Link to comment
Share on other sites

  • 4 weeks later...

I have posted OpenStreetMap  v14.0.5.9b that removes all the links to polyfill.io.

Our thanks to Ron Krzmarzick for providing the fix identified in cloudfare (v14.0.5.9a) and for testing v14.0.5.9b that removed all links to polyfill.io

Link to comment
Share on other sites

Katryne,

Sorry I only reworked the mod for TNG 14.0.5 since I am trying to get my own site upgraded to TNG 14.0.5

Edited to add -- The first 3 digits of the mod number are v14.0.5 which means that is the earliest version of TNG that the mod will install and work on.  

Link to comment
Share on other sites

Don't worry, I put back the "old" v.13.1.0.8j
But I do not understand a word of the 2 links that Justinhow posted.

Link to comment
Share on other sites

I re-installed my version 13.1.0.8j after modifying 2 files :

in the cfg file, I deleted 5 lines that mentionned polyfill (=10 occurences)

in the folder, in heatmap.com.php, I deleted 1 line that mentionned polyfill (=2 occurences)

It seems to be working well. Is this the right thing to do?

Link to comment
Share on other sites

Katryne,

That sounds right.  Since it does not look like I will get my production site which is also at TNG 14.0.4 upgraded any time soon, I created v13.1.0.9 of the mod  today, installed it on my production site, and have now posted on the TNG Wiki for those running TNG 13.1 through TNG 14.0.4

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...