PT-2020-21507 · Node.Js · Node.Js

Published

2020-09-03

·

Updated

2020-09-03

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions Node.js versions prior to 7.0
Description The issue is related to Uninitialized Memory Exposure, where the package incorrectly calculates the allocated Buffer size and does not trim the bytes written. This may allow attackers to access uninitialized memory containing sensitive data.
Recommendations Upgrade your Node.js version to a newer version to resolve the issue. Consider using an alternative package as a temporary workaround.

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

GHSA-V6GV-FG46-H89J

Affected Products

Node.Js