Description
Versions of base64url before 3.0.0 are vulnerable to to out-of-bounds reads as it allocates uninitialized Buffers when number is passed in input on Node.js 4.x and below.
Recommendation
Update the base64url package to the latest compatible version. Followings are version details:
- Affected version(s): < 3.0.0
- Patched version(s): 3.0.0
References
Could your website be exposed too?
SmartScanner can check your website for Out-of-bounds Read in base64url and gives you actionable findings to investigate.
Start a free scanRelated Issues
- OpenCC has an Out-of-bounds read when processing truncated UTF-8 input - Vulnerability
- Out-of-bounds Read in atob - CVE-2018-3745
- Open Chinese Convert subject to Denial of Service via Out-of-bounds Read - CVE-2018-16982
- Read the Docs vulnerable to Cross-Site Scripting (XSS) - Vulnerability
You might also like:
See something that needs correcting? Let us knowUpdated April 21, 2023


