Vulnerabilities

1 via 1 paths

Dependencies

50

Source

GitHub

Commit

6c0ea570

Find, fix and prevent vulnerabilities in your code.

Severity
  • 1
Status
  • 1
  • 0
  • 0

low severity
new

Improper Validation of Syntactic Correctness of Input

  • Vulnerable module: aws-sdk
  • Introduced through: aws-sdk@2.1693.0

Detailed paths

  • Introduced through: greenlock-storage-s3@cderche/greenlock-storage-s3#6c0ea5704e9d1666ef83ef663241500635f869f2 aws-sdk@2.1693.0

Overview

Affected versions of this package are vulnerable to Improper Validation of Syntactic Correctness of Input in the region input field. An attacker can cause AWS API calls to be routed to unintended or non-existent hosts by supplying an invalid value to this parameter.

##Workaround

This vulnerability can be mitigated by implementing proper input sanitization in application code or migrating to AWS SDK for JavaScript v3.

Remediation

There is no fixed version for aws-sdk.