Description
Trying to use js-imagediff from jsdeliver which complains about security issue in the package.
Js deliver download page wait some seconds and until the varning message is shown. It leads to the
Snyk report on the issue.
MEDIUM SEVERITY
Denial of Service (DoS)
Vulnerable module: canvas, Introduced through: [email protected]
Detailed paths
Introduced through: [email protected] › [email protected]
Remediation: Upgrade to [email protected].
Overview
canvas is a Cairo-backed Canvas implementation for Node.js.
Affected versions of this package are vulnerable to Denial of Service (DoS). Processing malicious JPEGs or GIFs files could crash the node process.
Denial of Service (DoS) vulnerability report
Maybe just an old version on Js deliver ?
It says 1.0.8 on the Js deliver page but in the code comments it says 1.0.3