Vulnerabilities

1 via 2 paths

Dependencies

4

Source

GitHub

Find, fix and prevent vulnerabilities in your code.

Severity
  • 1
Status
  • 1
  • 0
  • 0

medium severity
new

Improper Validation of Specified Quantity in Input

  • Vulnerable module: sprintf-js
  • Introduced through: argparse@1.0.10 and js-yaml@3.15.2

Detailed paths

  • Introduced through: reyaml-core@cedricpoon/reyaml-core › argparse@1.0.10 › sprintf-js@1.0.3
  • Introduced through: reyaml-core@cedricpoon/reyaml-core › js-yaml@3.15.2 › argparse@1.0.10 › sprintf-js@1.0.3

Overview

Affected versions of this package are vulnerable to Improper Validation of Specified Quantity in Input via unbounded precision specifiers passed without validation to the toFixed, toExponential, and toPrecision methods. An attacker who controls a format string can inject precision values exceeding ECMAScript limits, causing uncaught RangeError exceptions that abort the calling operation.

Remediation

There is no fixed version for sprintf-js.

References