GHSA-j4mr-9xw3-c9jx

Suggest an improvement
Source
https://github.com/advisories/GHSA-j4mr-9xw3-c9jx
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/05/GHSA-j4mr-9xw3-c9jx/GHSA-j4mr-9xw3-c9jx.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-j4mr-9xw3-c9jx
Downstream
Published
2019-05-31T23:47:01Z
Modified
2020-08-31T18:31:43Z
Summary
Out-of-bounds Read in base64-url
Details

Versions of base64-url before 2.0.0 are vulnerable to out-of-bounds read as it allocates uninitialized Buffers when number is passed in input.

Recommendation

Update to version 2.0.0 or later.

Database specific
{
    "cwe_ids":  [
        "CWE-125"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2019-05-31T23:45:33Z",
    "nvd_published_at":  null,
    "severity":  "HIGH"
}
References

Affected packages

npm / base64-url

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.0.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/05/GHSA-j4mr-9xw3-c9jx/GHSA-j4mr-9xw3-c9jx.json"