Ecosyste.ms: Advisories

An open API service providing security vulnerability metadata for many open source software ecosystems.

Security Advisories: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWo0bXItOXh3My1jOWp4

Out-of-bounds Read in base64-url

Versions of base64-url before 2.0.0 are vulnerable to out-of-bounds read as it allocates uninitialized Buffers when number is passed in input.

Recommendation

Update to version 2.0.0 or later.

Permalink: https://github.com/advisories/GHSA-j4mr-9xw3-c9jx
JSON: https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWo0bXItOXh3My1jOWp4
Source: GitHub Advisory Database
Origin: Unspecified
Severity: High
Classification: General
Published: almost 5 years ago
Updated: over 1 year ago


Identifiers: GHSA-j4mr-9xw3-c9jx
References: Blast Radius: 0.0

Affected Packages

npm:base64-url
Dependent packages: 245
Dependent repositories: 44,360
Downloads: 1,878,337 last month
Affected Version Ranges: < 2.0.0
Fixed in: 2.0.0
All affected versions: 1.0.0, 1.1.0, 1.2.0, 1.2.1, 1.2.2, 1.3.2, 1.3.3
All unaffected versions: 2.0.0, 2.0.1, 2.1.0, 2.2.0, 2.2.1, 2.2.2, 2.3.2, 2.3.3