This repository has been archived by the owner on Dec 9, 2023. It is now read-only.
CVE-2018-21270 (Medium) detected in stringstream-0.0.5.tgz #160
Labels
security vulnerability
Security vulnerability detected by WhiteSource
CVE-2018-21270 - Medium Severity Vulnerability
Vulnerable Library - stringstream-0.0.5.tgz
Encode and decode streams into string streams
Library home page: https://registry.npmjs.org/stringstream/-/stringstream-0.0.5.tgz
Path to dependency file: /Website/package.json
Path to vulnerable library: Website/node_modules/stringstream/package.json
Dependency Hierarchy:
Vulnerability Details
Versions less than 0.0.6 of the Node.js stringstream module are vulnerable to an out-of-bounds read because of allocation of uninitialized buffers when a number is passed in the input stream (when using Node.js 4.x).
Publish Date: 2020-12-03
URL: CVE-2018-21270
CVSS 3 Score Details (6.5)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Origin: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-21270
Release Date: 2020-12-03
Fix Resolution: 0.0.6
Step up your Open Source Security Game with WhiteSource here
The text was updated successfully, but these errors were encountered: