Vulnerabilities/

Out-of-bounds Read in njwt

Severity:
Low

Description

Versions of njwt prior to 1.0.0 are vulnerable to out-of-bounds reads when a number is passed into the base64urlEncode function.

On Node.js 6.x or lower this can expose sensitive information and on any other version of Node.js this creates a Denial of Service vulnerability.

Recommendation

Update the njwt package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
njwt
Anything's wrong? Let us know Last updated on January 09, 2023

This issue is available in SmartScanner Professional

See Pricing