GHSA-gg6m-fhqv-hg56

Suggest an improvement
Source
https://github.com/advisories/GHSA-gg6m-fhqv-hg56
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-gg6m-fhqv-hg56/GHSA-gg6m-fhqv-hg56.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-gg6m-fhqv-hg56
Aliases
  • CVE-2014-4179
Published
2020-09-01T15:15:36Z
Modified
2023-11-08T03:57:41Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Denial of Service in yar
Details

Versions of yar prior to 2.2.0 are affected by a denial of service vulnerability related to an invalid encrypted session cookie value.

When an invalid encryped session cookie value is provided, the process will crash.

Recommendation

Update to version 2.2.0 or later.

Database specific
{
    "cwe_ids":  [
        "CWE-400"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2020-08-31T18:09:03Z",
    "nvd_published_at":  null,
    "severity":  "HIGH"
}
References

Affected packages

npm / yar

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.2.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-gg6m-fhqv-hg56/GHSA-gg6m-fhqv-hg56.json"