Description
Versions of base64url before 3.0.0 are vulnerable to to out-of-bounds reads as it allocates uninitialized Buffers when number is passed in input on Node.js 4.x and below.
Recommendation
Update the base64url package to the latest compatible version. Followings are version details:
- Affected version(s): < 3.0.0
- Patched version(s): 3.0.0
References
Related Issues
- OpenCC has an Out-of-bounds read when processing truncated UTF-8 input - Vulnerability
- Out-of-bounds Read in atob - CVE-2018-3745
- Open Chinese Convert subject to Denial of Service via Out-of-bounds Read - CVE-2018-16982
- Read the Docs vulnerable to Cross-Site Scripting (XSS) - Vulnerability
You might also like:
- Tags:
- npm
- base64url
Anything's wrong? Let us know Last updated on April 21, 2023


