Book-Trading-Club icon indicating copy to clipboard operation
Book-Trading-Club copied to clipboard

WS-2018-0096 High Severity Vulnerability detected by WhiteSource

Open mend-bolt-for-github[bot] opened this issue 6 years ago • 0 comments

WS-2018-0096 - High Severity Vulnerability

Vulnerable Library - base64url-2.0.0.tgz

For encoding to/from base64urls

path: /tmp/git/Book-Trading-Club/node_modules/base64url/package.json

Library home page: https://registry.npmjs.org/base64url/-/base64url-2.0.0.tgz

Dependency Hierarchy:

  • jsonwebtoken-8.0.1.tgz (Root Library)
    • jws-3.1.4.tgz
      • :x: base64url-2.0.0.tgz (Vulnerable Library)

Vulnerability Details

Versions of base64url before 3.0.0 are vulnerable to to out-of-bounds reads as it allocates uninitialized Buffers when number is passed in input on Node.js 4.x and below.

Publish Date: 2018-05-16

URL: WS-2018-0096

CVSS 2 Score Details (7.1)

Base Score Metrics not available

Suggested Fix

Type: Upgrade version

Origin: https://hackerone.com/reports/321687

Release Date: 2019-01-24

Fix Resolution: 3.0.0


Step up your Open Source Security Game with WhiteSource here