Skip to content
This repository has been archived by the owner on Oct 23, 2019. It is now read-only.

Snyk report - Uninitialized Memory Exposure #29

Open
impactmass opened this issue Aug 16, 2018 · 2 comments
Open

Snyk report - Uninitialized Memory Exposure #29

impactmass opened this issue Aug 16, 2018 · 2 comments

Comments

@impactmass
Copy link
Owner

impactmass commented Aug 16, 2018

Vulnerable module: utile

Introduced through: prompt@1.0.0
Detailed paths and remediation
Introduced through:

cordova-rave@0.0.0-development › prompt@1.0.0 › utile@0.3.0
Remediation: No remediation path available.

Overview
utile is a drop-in replacement for util with some additional advantageous functions.

Affected versions of this package are vulnerable to Uninitialized Memory Exposure. A malicious user could extract sensitive data from uninitialized memory or to cause a DoS by passing in a large number, in setups where typed user input can be passed.

Note Uninitialized Memory Exposure impacts only Node.js 6.x or lower, Denial of Service impacts any Node.js version.

@impactmass
Copy link
Owner Author

Fixed in latest release 1.2.2

@impactmass
Copy link
Owner Author

Snyk still reports this in latest release

@impactmass impactmass reopened this Oct 17, 2018
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant