Vulnerabilities

2 via 2 paths

Dependencies

171

Source

GitHub

Find, fix and prevent vulnerabilities in your code.

Severity
  • 2
Status
  • 2
  • 0
  • 0

high severity

Inefficient Algorithmic Complexity

  • Vulnerable module: js-yaml
  • Introduced through: js-yaml@4.2.0

Detailed paths

  • Introduced through: kastell@kastelldev/kastell js-yaml@4.2.0
    Remediation: Upgrade to js-yaml@4.3.0.

Overview

js-yaml is a human-friendly data serialization language.

Affected versions of this package are vulnerable to Inefficient Algorithmic Complexity in merge key (<<) handling during YAML parsing, where each mapping in a chain re-enumerates the keys inherited from the previous mapping. An attacker can exhaust CPU and cause denial of service by supplying a document with N chained merge mappings, which forces roughly O(N^2) work for O(N) input. Exploitation requires the application to parse untrusted YAML with the default or YAML11 schema, under which merge keys are resolved.

Remediation

Upgrade js-yaml to version 3.15.0, 4.3.0 or higher.

References

high severity
new

Inefficient Algorithmic Complexity

  • Vulnerable module: js-yaml
  • Introduced through: js-yaml@4.2.0

Detailed paths

  • Introduced through: kastell@kastelldev/kastell js-yaml@4.2.0
    Remediation: Upgrade to js-yaml@4.3.1.

Overview

js-yaml is a human-friendly data serialization language.

Affected versions of this package are vulnerable to Inefficient Algorithmic Complexity through the yaml.load process. An attacker can cause excessive CPU consumption and block the event loop by providing a specially crafted YAML document containing a large !!omap sequence.

Remediation

Upgrade js-yaml to version 3.15.1, 4.3.1 or higher.

References