OSV 1.4.0 · github-reviewed · 修改于 2020-09-01 02:32
发布时间
2020-09-02 05:08
GitHub 审查时间
2020-09-01 02:32
NVD 发布时间
—
源文件
advisories/github-reviewed/2020/09/GHSA-g3qw-9pgp-xpj4/GHSA-g3qw-9pgp-xpj4.json
Versions of njwt prior to 1.0.0 are vulnerable to out-of-bounds reads when a number is passed into the base64urlEncode function.
On Node.js 6.x or lower this can expose sensitive information and on any other version of Node.js this creates a Denial of Service vulnerability.
Upgrade to version 1.0.0.