Vulnerabilities/

Out-of-bounds Read in base64url

Severity:
Medium

Description

Versions of base64url before 3.0.0 are vulnerable to to out-of-bounds reads as it allocates uninitialized Buffers when number is passed in input on Node.js 4.x and below.

Recommendation

Update the base64url package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
base64url
Anything's wrong? Let us know Last updated on April 21, 2023