Ecosyste.ms advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
An open API service providing security vulnerability metadata for many open source software ecosystems.
Out-of-bounds Read in njwt
Versions of njwt
prior to 1.0.0 are vulnerable to out-of-bounds reads when a number is passed into the base64urlEncode
function.
On Node.js 6.x or lower this can expose sensitive information and on any other version of Node.js this creates a Denial of Service vulnerability.
Upgrade to version 1.0.0.
Permalink: https://github.com/advisories/GHSA-g3qw-9pgp-xpj4