GHSA-v6gv-fg46-h89j

Suggest an improvement
Source
https://github.com/advisories/GHSA-v6gv-fg46-h89j
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-v6gv-fg46-h89j/GHSA-v6gv-fg46-h89j.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-v6gv-fg46-h89j
Published
2020-09-03T16:48:36Z
Modified
2020-08-31T18:43:51Z
Summary
Sensitive Data Exposure in put
Details

All versions of put are vulnerable to Uninitialized Memory Exposure. The package incorrectly calculates the allocated Buffer size and does not trim the bytes written, which may allow attackers to access uninitialized memory containing sensitive data. This vulnerability only affects versions of Node.js <=6.x.

Recommendation

Upgrade your Node.js version or consider using an alternative package.

Database specific
{
    "cwe_ids":  [
        "CWE-200"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2020-08-31T18:43:51Z",
    "nvd_published_at":  null,
    "severity":  "LOW"
}
References

Affected packages

npm / put

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-v6gv-fg46-h89j/GHSA-v6gv-fg46-h89j.json"