Vulnerabilities |
18 via 20 paths |
|---|---|
Dependencies |
129 |
Source |
GitHub |
Find, fix and prevent vulnerabilities in your code.
high severity
new
- Vulnerable module: @xmldom/xmldom
- Introduced through: expo-linking@6.3.1
Detailed paths
-
Introduced through: @bluebase/plugin-react-navigation@BlueBaseJS/plugin-react-navigation › expo-linking@6.3.1 › expo-constants@16.0.2 › @expo/config@9.0.4 › @expo/config-plugins@8.0.11 › @expo/plist@0.1.3 › @xmldom/xmldom@0.7.13Remediation: Upgrade to expo-linking@7.1.0.
Overview
@xmldom/xmldom is a javascript ponyfill to provide the following APIs that are present in modern browsers to other runtimes. Since version 0.7.0 this package is published to npm as @xmldom/xmldom and no longer as xmldom
Affected versions of this package are vulnerable to XML Injection in the Document.createProcessingInstruction function. An attacker can inject arbitrary XML structure by supplying specially crafted input containing invalid XML-name characters, which can break the processing-instruction boundary during serialization.
Remediation
Upgrade @xmldom/xmldom to version 0.8.15, 0.9.12 or higher.
References
high severity
new
- Vulnerable module: @xmldom/xmldom
- Introduced through: expo-linking@6.3.1
Detailed paths
-
Introduced through: @bluebase/plugin-react-navigation@BlueBaseJS/plugin-react-navigation › expo-linking@6.3.1 › expo-constants@16.0.2 › @expo/config@9.0.4 › @expo/config-plugins@8.0.11 › @expo/plist@0.1.3 › @xmldom/xmldom@0.7.13Remediation: Upgrade to expo-linking@7.1.0.
Overview
@xmldom/xmldom is a javascript ponyfill to provide the following APIs that are present in modern browsers to other runtimes. Since version 0.7.0 this package is published to npm as @xmldom/xmldom and no longer as xmldom
Affected versions of this package are vulnerable to Allocation of Resources Without Limits or Throttling through the appendElement function in lib/sax.js when handling XML documents with deeply nested elements that declare new namespace prefixes. An attacker can cause excessive memory consumption by submitting specially crafted XML input that leads to quadratic growth in namespace-map storage, potentially resulting in process heap exhaustion.
Remediation
Upgrade @xmldom/xmldom to version 0.8.15, 0.9.12 or higher.
References
high severity
new
- Vulnerable module: @xmldom/xmldom
- Introduced through: expo-linking@6.3.1
Detailed paths
-
Introduced through: @bluebase/plugin-react-navigation@BlueBaseJS/plugin-react-navigation › expo-linking@6.3.1 › expo-constants@16.0.2 › @expo/config@9.0.4 › @expo/config-plugins@8.0.11 › @expo/plist@0.1.3 › @xmldom/xmldom@0.7.13Remediation: Upgrade to expo-linking@7.1.0.
Overview
@xmldom/xmldom is a javascript ponyfill to provide the following APIs that are present in modern browsers to other runtimes. Since version 0.7.0 this package is published to npm as @xmldom/xmldom and no longer as xmldom
Affected versions of this package are vulnerable to Allocation of Resources Without Limits or Throttling via the parseElementStartPart function and normalization. An attacker can cause excessive resource consumption by providing specially crafted XML input that triggers repeated rescanning or merging of adjacent text nodes.
Remediation
Upgrade @xmldom/xmldom to version 0.8.15, 0.9.12 or higher.
References
high severity
new
- Vulnerable module: @xmldom/xmldom
- Introduced through: expo-linking@6.3.1
Detailed paths
-
Introduced through: @bluebase/plugin-react-navigation@BlueBaseJS/plugin-react-navigation › expo-linking@6.3.1 › expo-constants@16.0.2 › @expo/config@9.0.4 › @expo/config-plugins@8.0.11 › @expo/plist@0.1.3 › @xmldom/xmldom@0.7.13Remediation: Upgrade to expo-linking@7.1.0.
Overview
@xmldom/xmldom is a javascript ponyfill to provide the following APIs that are present in modern browsers to other runtimes. Since version 0.7.0 this package is published to npm as @xmldom/xmldom and no longer as xmldom
Affected versions of this package are vulnerable to Inefficient Algorithmic Complexity in the DOMParser.parseFromString function. An attacker can cause significant performance degradation and stall the Node.js event loop by submitting XML documents containing elements with a large number of unique attributes.
Remediation
Upgrade @xmldom/xmldom to version 0.8.15, 0.9.12 or higher.
References
high severity
new
- Vulnerable module: @xmldom/xmldom
- Introduced through: expo-linking@6.3.1
Detailed paths
-
Introduced through: @bluebase/plugin-react-navigation@BlueBaseJS/plugin-react-navigation › expo-linking@6.3.1 › expo-constants@16.0.2 › @expo/config@9.0.4 › @expo/config-plugins@8.0.11 › @expo/plist@0.1.3 › @xmldom/xmldom@0.7.13
Overview
@xmldom/xmldom is a javascript ponyfill to provide the following APIs that are present in modern browsers to other runtimes. Since version 0.7.0 this package is published to npm as @xmldom/xmldom and no longer as xmldom
Affected versions of this package are vulnerable to Regular Expression Denial of Service (ReDoS) via inefficient handling of unterminated processing instructions in XML input. An attacker can cause excessive resource consumption and disrupt service availability by submitting specially crafted XML data that triggers quadratic backtracking in the regular expression engine.
Details
Denial of Service (DoS) describes a family of attacks, all aimed at making a system inaccessible to its original and legitimate users. There are many types of DoS attacks, ranging from trying to clog the network pipes to the system by generating a large volume of traffic from many machines (a Distributed Denial of Service - DDoS - attack) to sending crafted requests that cause a system to crash or take a disproportional amount of time to process.
The Regular expression Denial of Service (ReDoS) is a type of Denial of Service attack. Regular expressions are incredibly powerful, but they aren't very intuitive and can ultimately end up making it easy for attackers to take your site down.
Let’s take the following regular expression as an example:
regex = /A(B|C+)+D/
This regular expression accomplishes the following:
AThe string must start with the letter 'A'(B|C+)+The string must then follow the letter A with either the letter 'B' or some number of occurrences of the letter 'C' (the+matches one or more times). The+at the end of this section states that we can look for one or more matches of this section.DFinally, we ensure this section of the string ends with a 'D'
The expression would match inputs such as ABBD, ABCCCCD, ABCBCCCD and ACCCCCD
It most cases, it doesn't take very long for a regex engine to find a match:
$ time node -e '/A(B|C+)+D/.test("ACCCCCCCCCCCCCCCCCCCCCCCCCCCCD")'
0.04s user 0.01s system 95% cpu 0.052 total
$ time node -e '/A(B|C+)+D/.test("ACCCCCCCCCCCCCCCCCCCCCCCCCCCCX")'
1.79s user 0.02s system 99% cpu 1.812 total
The entire process of testing it against a 30 characters long string takes around ~52ms. But when given an invalid string, it takes nearly two seconds to complete the test, over ten times as long as it took to test a valid string. The dramatic difference is due to the way regular expressions get evaluated.
Most Regex engines will work very similarly (with minor differences). The engine will match the first possible way to accept the current character and proceed to the next one. If it then fails to match the next one, it will backtrack and see if there was another way to digest the previous character. If it goes too far down the rabbit hole only to find out the string doesn’t match in the end, and if many characters have multiple valid regex paths, the number of backtracking steps can become very large, resulting in what is known as catastrophic backtracking.
Let's look at how our expression runs into this problem, using a shorter string: "ACCCX". While it seems fairly straightforward, there are still four different ways that the engine could match those three C's:
- CCC
- CC+C
- C+CC
- C+C+C.
The engine has to try each of those combinations to see if any of them potentially match against the expression. When you combine that with the other steps the engine must take, we can use RegEx 101 debugger to see the engine has to take a total of 38 steps before it can determine the string doesn't match.
From there, the number of steps the engine must use to validate a string just continues to grow.
| String | Number of C's | Number of steps |
|---|---|---|
| ACCCX | 3 | 38 |
| ACCCCX | 4 | 71 |
| ACCCCCX | 5 | 136 |
| ACCCCCCCCCCCCCCX | 14 | 65,553 |
By the time the string includes 14 C's, the engine has to take over 65,000 steps just to see if the string is valid. These extreme situations can cause them to work very slowly (exponentially related to input size, as shown above), allowing an attacker to exploit this and can cause the service to excessively consume CPU, resulting in a Denial of Service.
Remediation
Upgrade @xmldom/xmldom to version 0.9.11 or higher.
References
high severity
new
- Vulnerable module: @xmldom/xmldom
- Introduced through: expo-linking@6.3.1
Detailed paths
-
Introduced through: @bluebase/plugin-react-navigation@BlueBaseJS/plugin-react-navigation › expo-linking@6.3.1 › expo-constants@16.0.2 › @expo/config@9.0.4 › @expo/config-plugins@8.0.11 › @expo/plist@0.1.3 › @xmldom/xmldom@0.7.13Remediation: Upgrade to expo-linking@7.1.0.
Overview
@xmldom/xmldom is a javascript ponyfill to provide the following APIs that are present in modern browsers to other runtimes. Since version 0.7.0 this package is published to npm as @xmldom/xmldom and no longer as xmldom
Affected versions of this package are vulnerable to Regular Expression Denial of Service (ReDoS) via the parseFromString function. An attacker can cause excessive resource consumption and stall the event loop by submitting specially crafted XML input containing long whitespace runs in end tags.
Details
Denial of Service (DoS) describes a family of attacks, all aimed at making a system inaccessible to its original and legitimate users. There are many types of DoS attacks, ranging from trying to clog the network pipes to the system by generating a large volume of traffic from many machines (a Distributed Denial of Service - DDoS - attack) to sending crafted requests that cause a system to crash or take a disproportional amount of time to process.
The Regular expression Denial of Service (ReDoS) is a type of Denial of Service attack. Regular expressions are incredibly powerful, but they aren't very intuitive and can ultimately end up making it easy for attackers to take your site down.
Let’s take the following regular expression as an example:
regex = /A(B|C+)+D/
This regular expression accomplishes the following:
AThe string must start with the letter 'A'(B|C+)+The string must then follow the letter A with either the letter 'B' or some number of occurrences of the letter 'C' (the+matches one or more times). The+at the end of this section states that we can look for one or more matches of this section.DFinally, we ensure this section of the string ends with a 'D'
The expression would match inputs such as ABBD, ABCCCCD, ABCBCCCD and ACCCCCD
It most cases, it doesn't take very long for a regex engine to find a match:
$ time node -e '/A(B|C+)+D/.test("ACCCCCCCCCCCCCCCCCCCCCCCCCCCCD")'
0.04s user 0.01s system 95% cpu 0.052 total
$ time node -e '/A(B|C+)+D/.test("ACCCCCCCCCCCCCCCCCCCCCCCCCCCCX")'
1.79s user 0.02s system 99% cpu 1.812 total
The entire process of testing it against a 30 characters long string takes around ~52ms. But when given an invalid string, it takes nearly two seconds to complete the test, over ten times as long as it took to test a valid string. The dramatic difference is due to the way regular expressions get evaluated.
Most Regex engines will work very similarly (with minor differences). The engine will match the first possible way to accept the current character and proceed to the next one. If it then fails to match the next one, it will backtrack and see if there was another way to digest the previous character. If it goes too far down the rabbit hole only to find out the string doesn’t match in the end, and if many characters have multiple valid regex paths, the number of backtracking steps can become very large, resulting in what is known as catastrophic backtracking.
Let's look at how our expression runs into this problem, using a shorter string: "ACCCX". While it seems fairly straightforward, there are still four different ways that the engine could match those three C's:
- CCC
- CC+C
- C+CC
- C+C+C.
The engine has to try each of those combinations to see if any of them potentially match against the expression. When you combine that with the other steps the engine must take, we can use RegEx 101 debugger to see the engine has to take a total of 38 steps before it can determine the string doesn't match.
From there, the number of steps the engine must use to validate a string just continues to grow.
| String | Number of C's | Number of steps |
|---|---|---|
| ACCCX | 3 | 38 |
| ACCCCX | 4 | 71 |
| ACCCCCX | 5 | 136 |
| ACCCCCCCCCCCCCCX | 14 | 65,553 |
By the time the string includes 14 C's, the engine has to take over 65,000 steps just to see if the string is valid. These extreme situations can cause them to work very slowly (exponentially related to input size, as shown above), allowing an attacker to exploit this and can cause the service to excessively consume CPU, resulting in a Denial of Service.
Remediation
Upgrade @xmldom/xmldom to version 0.8.15 or higher.
References
high severity
- Vulnerable module: @xmldom/xmldom
- Introduced through: expo-linking@6.3.1
Detailed paths
-
Introduced through: @bluebase/plugin-react-navigation@BlueBaseJS/plugin-react-navigation › expo-linking@6.3.1 › expo-constants@16.0.2 › @expo/config@9.0.4 › @expo/config-plugins@8.0.11 › @expo/plist@0.1.3 › @xmldom/xmldom@0.7.13Remediation: Upgrade to expo-linking@7.1.0.
Overview
@xmldom/xmldom is a javascript ponyfill to provide the following APIs that are present in modern browsers to other runtimes. Since version 0.7.0 this package is published to npm as @xmldom/xmldom and no longer as xmldom
Affected versions of this package are vulnerable to Uncontrolled Recursion in the recursive processing of deeply nested XML documents by several DOM-related operations, including normalize, serializeToString, getElementsByTagName, getElementsByTagNameNS, getElementsByClassName, getElementById, cloneNode, importNode, textContent, and isEqualNode. An attacker can cause the application to crash or become unresponsive by submitting a valid, deeply nested XML payload that triggers uncontrolled recursion and stack exhaustion.
PoC
const { DOMParser, XMLSerializer } = require('@xmldom/xmldom');
const depth = 5000;
const xml = '<a>'.repeat(depth) + '</a>'.repeat(depth);
const doc = new DOMParser().parseFromString(xml, 'text/xml');
new XMLSerializer().serializeToString(doc);
// RangeError: Maximum call stack size exceeded
Remediation
Upgrade @xmldom/xmldom to version 0.8.13, 0.9.10 or higher.
References
high severity
- Vulnerable module: @xmldom/xmldom
- Introduced through: expo-linking@6.3.1
Detailed paths
-
Introduced through: @bluebase/plugin-react-navigation@BlueBaseJS/plugin-react-navigation › expo-linking@6.3.1 › expo-constants@16.0.2 › @expo/config@9.0.4 › @expo/config-plugins@8.0.11 › @expo/plist@0.1.3 › @xmldom/xmldom@0.7.13Remediation: Upgrade to expo-linking@7.1.0.
Overview
@xmldom/xmldom is a javascript ponyfill to provide the following APIs that are present in modern browsers to other runtimes. Since version 0.7.0 this package is published to npm as @xmldom/xmldom and no longer as xmldom
Affected versions of this package are vulnerable to XML Injection due to unvalidated comment serialization. When an application uses the package to create an XML comment from untrusted user input, the package fails to sanitize comment-breaking sequences (like -->). An attacker can input --> to terminate the comment prematurely. Once the comment is broken out of, any text the attacker places after the --> is treated as "live" XML markup by the serializer rather than harmless comment text.
PoC
const { DOMImplementation, DOMParser, XMLSerializer } = require('@xmldom/xmldom');
const doc = new DOMImplementation().createDocument(null, 'root', null);
doc.documentElement.appendChild(
doc.createComment('--><injected attr="1"/><!--')
);
const xml = new XMLSerializer().serializeToString(doc);
console.log(xml);
// <root><!----><injected attr="1"/><!----></root>
const reparsed = new DOMParser().parseFromString(xml, 'text/xml');
console.log(reparsed.documentElement.childNodes.item(1).nodeName);
// injected
Remediation
Upgrade @xmldom/xmldom to version 0.8.13, 0.9.10 or higher.
References
high severity
- Vulnerable module: @xmldom/xmldom
- Introduced through: expo-linking@6.3.1
Detailed paths
-
Introduced through: @bluebase/plugin-react-navigation@BlueBaseJS/plugin-react-navigation › expo-linking@6.3.1 › expo-constants@16.0.2 › @expo/config@9.0.4 › @expo/config-plugins@8.0.11 › @expo/plist@0.1.3 › @xmldom/xmldom@0.7.13Remediation: Upgrade to expo-linking@7.1.0.
Overview
@xmldom/xmldom is a javascript ponyfill to provide the following APIs that are present in modern browsers to other runtimes. Since version 0.7.0 this package is published to npm as @xmldom/xmldom and no longer as xmldom
Affected versions of this package are vulnerable to XML Injection in the serialization of DocumentType nodes when attacker-controlled values are provided to the publicId, systemId, or internalSubset fields. An attacker can inject arbitrary XML markup into the serialized output by supplying specially crafted input to these fields, potentially leading to the injection of malicious DOCTYPE declarations or markup outside the intended context.
Note:
This is only exploitable if untrusted data is passed programmatically to createDocumentType or written directly to the relevant properties and then serialized without enabling strict validation.
Workaround
This vulnerability can be mitigated by passing the option { requireWellFormed: true } to XMLSerializer.serializeToString() to enforce validation of the affected fields.
Remediation
Upgrade @xmldom/xmldom to version 0.8.13, 0.9.10 or higher.
References
high severity
- Vulnerable module: @xmldom/xmldom
- Introduced through: expo-linking@6.3.1
Detailed paths
-
Introduced through: @bluebase/plugin-react-navigation@BlueBaseJS/plugin-react-navigation › expo-linking@6.3.1 › expo-constants@16.0.2 › @expo/config@9.0.4 › @expo/config-plugins@8.0.11 › @expo/plist@0.1.3 › @xmldom/xmldom@0.7.13Remediation: Upgrade to expo-linking@7.1.0.
Overview
@xmldom/xmldom is a javascript ponyfill to provide the following APIs that are present in modern browsers to other runtimes. Since version 0.7.0 this package is published to npm as @xmldom/xmldom and no longer as xmldom
Affected versions of this package are vulnerable to XML Injection via the createProcessingInstruction function. An attacker can inject arbitrary XML nodes into the serialized output by supplying specially crafted data containing the PI-closing sequence, which is not validated or neutralized during serialization. This can alter the structure and meaning of generated XML documents, potentially impacting workflows that store, forward, sign, or parse XML.
Note:
This is only exploitable if the serialization is performed without passing the { requireWellFormed: true } option.
PoC
const { DOMImplementation, XMLSerializer } = require('@xmldom/xmldom');
const doc = new DOMImplementation().createDocument(null, 'r', null);
doc.documentElement.appendChild(
doc.createProcessingInstruction('a', '?><z/><?q ')
);
console.log(new XMLSerializer().serializeToString(doc));
// <r><?a ?><z/><?q ?></r>
// ^^^^ injected <z/> element is active markup
Remediation
Upgrade @xmldom/xmldom to version 0.8.13, 0.9.10 or higher.
References
high severity
new
- Vulnerable module: @xmldom/xmldom
- Introduced through: expo-linking@6.3.1
Detailed paths
-
Introduced through: @bluebase/plugin-react-navigation@BlueBaseJS/plugin-react-navigation › expo-linking@6.3.1 › expo-constants@16.0.2 › @expo/config@9.0.4 › @expo/config-plugins@8.0.11 › @expo/plist@0.1.3 › @xmldom/xmldom@0.7.13Remediation: Upgrade to expo-linking@7.1.0.
Overview
@xmldom/xmldom is a javascript ponyfill to provide the following APIs that are present in modern browsers to other runtimes. Since version 0.7.0 this package is published to npm as @xmldom/xmldom and no longer as xmldom
Affected versions of this package are vulnerable to XML Injection via the createElement method. An attacker can inject arbitrary attributes, elements, or processing instructions into serialized XML or HTML by supplying crafted tag names, potentially leading to execution of malicious scripts in environments that consume the serialized output.
Remediation
Upgrade @xmldom/xmldom to version 0.8.14, 0.9.11 or higher.
References
high severity
new
- Vulnerable module: @xmldom/xmldom
- Introduced through: expo-linking@6.3.1
Detailed paths
-
Introduced through: @bluebase/plugin-react-navigation@BlueBaseJS/plugin-react-navigation › expo-linking@6.3.1 › expo-constants@16.0.2 › @expo/config@9.0.4 › @expo/config-plugins@8.0.11 › @expo/plist@0.1.3 › @xmldom/xmldom@0.7.13Remediation: Upgrade to expo-linking@7.1.0.
Overview
@xmldom/xmldom is a javascript ponyfill to provide the following APIs that are present in modern browsers to other runtimes. Since version 0.7.0 this package is published to npm as @xmldom/xmldom and no longer as xmldom
Affected versions of this package are vulnerable to XML Injection via the setAttribute method. An attacker can inject arbitrary attribute names, including those containing event handlers or namespace declarations, by supplying crafted input that bypasses validation checks.
Remediation
Upgrade @xmldom/xmldom to version 0.8.14, 0.9.11 or higher.
References
high severity
new
- Vulnerable module: @xmldom/xmldom
- Introduced through: expo-linking@6.3.1
Detailed paths
-
Introduced through: @bluebase/plugin-react-navigation@BlueBaseJS/plugin-react-navigation › expo-linking@6.3.1 › expo-constants@16.0.2 › @expo/config@9.0.4 › @expo/config-plugins@8.0.11 › @expo/plist@0.1.3 › @xmldom/xmldom@0.7.13Remediation: Upgrade to expo-linking@7.1.0.
Overview
@xmldom/xmldom is a javascript ponyfill to provide the following APIs that are present in modern browsers to other runtimes. Since version 0.7.0 this package is published to npm as @xmldom/xmldom and no longer as xmldom
Affected versions of this package are vulnerable to XML Injection via improper validation of the name property in the DocumentType node when requireWellFormed is set to true. An attacker can inject arbitrary markup into the output by supplying a crafted value to the name property, potentially leading to the injection of sibling elements or manipulation of the document structure.
Remediation
Upgrade @xmldom/xmldom to version 0.8.15, 0.9.12 or higher.
References
high severity
- Vulnerable module: @xmldom/xmldom
- Introduced through: expo-linking@6.3.1
Detailed paths
-
Introduced through: @bluebase/plugin-react-navigation@BlueBaseJS/plugin-react-navigation › expo-linking@6.3.1 › expo-constants@16.0.2 › @expo/config@9.0.4 › @expo/config-plugins@8.0.11 › @expo/plist@0.1.3 › @xmldom/xmldom@0.7.13Remediation: Upgrade to expo-linking@7.1.0.
Overview
@xmldom/xmldom is a javascript ponyfill to provide the following APIs that are present in modern browsers to other runtimes. Since version 0.7.0 this package is published to npm as @xmldom/xmldom and no longer as xmldom
Affected versions of this package are vulnerable to XML Injection via the XMLSerializer() function. An attacker can manipulate the structure and integrity of generated XML documents by injecting attacker-controlled markup containing the CDATA terminator ]]> through CDATA section content, which is not properly validated or sanitized during serialization. This can result in unauthorized XML elements or attributes being inserted, potentially leading to business logic manipulation or privilege escalation in downstream consumers.
Remediation
Upgrade @xmldom/xmldom to version 0.8.12, 0.9.9 or higher.
References
medium severity
new
- Vulnerable module: @xmldom/xmldom
- Introduced through: expo-linking@6.3.1
Detailed paths
-
Introduced through: @bluebase/plugin-react-navigation@BlueBaseJS/plugin-react-navigation › expo-linking@6.3.1 › expo-constants@16.0.2 › @expo/config@9.0.4 › @expo/config-plugins@8.0.11 › @expo/plist@0.1.3 › @xmldom/xmldom@0.7.13Remediation: Upgrade to expo-linking@7.1.0.
Overview
@xmldom/xmldom is a javascript ponyfill to provide the following APIs that are present in modern browsers to other runtimes. Since version 0.7.0 this package is published to npm as @xmldom/xmldom and no longer as xmldom
Affected versions of this package are vulnerable to Improper Validation of Syntactic Correctness of Input via the parseFromString function. An attacker can bypass well-formedness validation by submitting XML data containing an end tag with a line break and trailing content, which is silently accepted and processed without error reporting.
Remediation
Upgrade @xmldom/xmldom to version 0.8.15, 0.9.12 or higher.
References
medium severity
new
- Vulnerable module: @xmldom/xmldom
- Introduced through: expo-linking@6.3.1
Detailed paths
-
Introduced through: @bluebase/plugin-react-navigation@BlueBaseJS/plugin-react-navigation › expo-linking@6.3.1 › expo-constants@16.0.2 › @expo/config@9.0.4 › @expo/config-plugins@8.0.11 › @expo/plist@0.1.3 › @xmldom/xmldom@0.7.13Remediation: Upgrade to expo-linking@7.1.0.
Overview
@xmldom/xmldom is a javascript ponyfill to provide the following APIs that are present in modern browsers to other runtimes. Since version 0.7.0 this package is published to npm as @xmldom/xmldom and no longer as xmldom
Affected versions of this package are vulnerable to Improper Encoding or Escaping of Output in the serializeToString function. An attacker can inject arbitrary XML markup by creating an EntityReference node with an invalid nodeName and directly serializing it with requireWellFormed: true.
Note: This is only exploitable if the application explicitly creates and serializes an EntityReference node, as the parser does not generate these nodes by default and element-child insertion is rejected.
Remediation
Upgrade @xmldom/xmldom to version 0.8.15, 0.9.12 or higher.
References
medium severity
- Vulnerable module: uuid
- Introduced through: expo-linking@6.3.1
Detailed paths
-
Introduced through: @bluebase/plugin-react-navigation@BlueBaseJS/plugin-react-navigation › expo-linking@6.3.1 › expo-constants@16.0.2 › @expo/config@9.0.4 › @expo/config-plugins@8.0.11 › xcode@3.0.1 › uuid@7.0.3
Overview
uuid is a RFC4122 (v1, v4, and v5) compliant UUID library.
Affected versions of this package are vulnerable to Improper Validation of Specified Index, Position, or Offset in Input due to accepting external output buffers but not rejecting out-of-range writes (small buf or large offset). This inconsistency allows silent partial writes into caller-provided buffers.
PoC
cd /home/StrawHat/uuid
npm ci
npm run build
node --input-type=module -e "
import {v4,v5,v6} from './dist-node/index.js';
const ns='6ba7b810-9dad-11d1-80b4-00c04fd430c8';
for (const [name,fn] of [
['v4',()=>v4({},new Uint8Array(8),4)],
['v5',()=>v5('x',ns,new Uint8Array(8),4)],
['v6',()=>v6({},new Uint8Array(8),4)],
]) {
try { fn(); console.log(name,'NO_THROW'); }
catch(e){ console.log(name,'THREW',e.name); }
}"
Remediation
Upgrade uuid to version 11.1.1, 14.0.0 or higher.
References
medium severity
- Vulnerable module: inflight
- Introduced through: expo-linking@6.3.1
Detailed paths
-
Introduced through: @bluebase/plugin-react-navigation@BlueBaseJS/plugin-react-navigation › expo-linking@6.3.1 › expo-constants@16.0.2 › @expo/config@9.0.4 › glob@7.1.6 › inflight@1.0.6
-
Introduced through: @bluebase/plugin-react-navigation@BlueBaseJS/plugin-react-navigation › expo-linking@6.3.1 › expo-constants@16.0.2 › @expo/config@9.0.4 › @expo/config-plugins@8.0.11 › glob@7.1.6 › inflight@1.0.6
-
Introduced through: @bluebase/plugin-react-navigation@BlueBaseJS/plugin-react-navigation › expo-linking@6.3.1 › expo-constants@16.0.2 › @expo/config@9.0.4 › sucrase@3.34.0 › glob@7.1.6 › inflight@1.0.6
Overview
Affected versions of this package are vulnerable to Missing Release of Resource after Effective Lifetime via the makeres function due to improperly deleting keys from the reqs object after execution of callbacks. This behavior causes the keys to remain in the reqs object, which leads to resource exhaustion.
Exploiting this vulnerability results in crashing the node process or in the application crash.
Note: This library is not maintained, and currently, there is no fix for this issue. To overcome this vulnerability, several dependent packages have eliminated the use of this library.
To trigger the memory leak, an attacker would need to have the ability to execute or influence the asynchronous operations that use the inflight module within the application. This typically requires access to the internal workings of the server or application, which is not commonly exposed to remote users. Therefore, “Attack vector” is marked as “Local”.
PoC
const inflight = require('inflight');
function testInflight() {
let i = 0;
function scheduleNext() {
let key = `key-${i++}`;
const callback = () => {
};
for (let j = 0; j < 1000000; j++) {
inflight(key, callback);
}
setImmediate(scheduleNext);
}
if (i % 100 === 0) {
console.log(process.memoryUsage());
}
scheduleNext();
}
testInflight();
Remediation
There is no fixed version for inflight.