Skip to content

Security - Medium severity - Vulnerable module: [email protected] #69

Open
@vbdata

Description

@vbdata

Trying to use js-imagediff from jsdeliver which complains about security issue in the package.

Js deliver download page wait some seconds and until the varning message is shown. It leads to the
Snyk report on the issue.

MEDIUM SEVERITY
Denial of Service (DoS)
Vulnerable module: canvas, Introduced through: [email protected]

Detailed paths
Introduced through: [email protected][email protected]

Remediation: Upgrade to [email protected].

Overview
canvas is a Cairo-backed Canvas implementation for Node.js.

Affected versions of this package are vulnerable to Denial of Service (DoS). Processing malicious JPEGs or GIFs files could crash the node process.

Denial of Service (DoS) vulnerability report

Maybe just an old version on Js deliver ?
It says 1.0.8 on the Js deliver page but in the code comments it says 1.0.3

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions