Vulnerabilities

1 via 45 paths

Dependencies

113

Source

GitHub

Commit

22cec069

Find, fix and prevent vulnerabilities in your code.

Severity
  • 1
Status
  • 1
  • 0
  • 0

medium severity
new

Buffer Overflow

  • Vulnerable module: fast-xml-parser
  • Introduced through: @aws-sdk/client-s3@3.986.0 and @aws-sdk/s3-request-presigner@3.989.0

Detailed paths

  • Introduced through: @parse/s3-files-adapter@parse-community/parse-server-s3-adapter#22cec069aafb57dd68bdbd89b5c9575e4cca801a @aws-sdk/client-s3@3.986.0 @aws-sdk/core@3.973.15 @aws-sdk/xml-builder@3.972.8 fast-xml-parser@5.3.6
  • Introduced through: @parse/s3-files-adapter@parse-community/parse-server-s3-adapter#22cec069aafb57dd68bdbd89b5c9575e4cca801a @aws-sdk/client-s3@3.986.0 @aws-sdk/middleware-user-agent@3.972.15 @aws-sdk/core@3.973.15 @aws-sdk/xml-builder@3.972.8 fast-xml-parser@5.3.6
  • Introduced through: @parse/s3-files-adapter@parse-community/parse-server-s3-adapter#22cec069aafb57dd68bdbd89b5c9575e4cca801a @aws-sdk/client-s3@3.986.0 @aws-sdk/middleware-flexible-checksums@3.973.1 @aws-sdk/core@3.973.15 @aws-sdk/xml-builder@3.972.8 fast-xml-parser@5.3.6
  • Introduced through: @parse/s3-files-adapter@parse-community/parse-server-s3-adapter#22cec069aafb57dd68bdbd89b5c9575e4cca801a @aws-sdk/client-s3@3.986.0 @aws-sdk/middleware-sdk-s3@3.972.15 @aws-sdk/core@3.973.15 @aws-sdk/xml-builder@3.972.8 fast-xml-parser@5.3.6
  • Introduced through: @parse/s3-files-adapter@parse-community/parse-server-s3-adapter#22cec069aafb57dd68bdbd89b5c9575e4cca801a @aws-sdk/client-s3@3.986.0 @aws-sdk/credential-provider-node@3.972.14 @aws-sdk/credential-provider-env@3.972.13 @aws-sdk/core@3.973.15 @aws-sdk/xml-builder@3.972.8 fast-xml-parser@5.3.6
  • Introduced through: @parse/s3-files-adapter@parse-community/parse-server-s3-adapter#22cec069aafb57dd68bdbd89b5c9575e4cca801a @aws-sdk/client-s3@3.986.0 @aws-sdk/credential-provider-node@3.972.14 @aws-sdk/credential-provider-http@3.972.15 @aws-sdk/core@3.973.15 @aws-sdk/xml-builder@3.972.8 fast-xml-parser@5.3.6
  • Introduced through: @parse/s3-files-adapter@parse-community/parse-server-s3-adapter#22cec069aafb57dd68bdbd89b5c9575e4cca801a @aws-sdk/client-s3@3.986.0 @aws-sdk/util-user-agent-node@3.973.0 @aws-sdk/middleware-user-agent@3.972.15 @aws-sdk/core@3.973.15 @aws-sdk/xml-builder@3.972.8 fast-xml-parser@5.3.6
  • Introduced through: @parse/s3-files-adapter@parse-community/parse-server-s3-adapter#22cec069aafb57dd68bdbd89b5c9575e4cca801a @aws-sdk/client-s3@3.986.0 @aws-sdk/credential-provider-node@3.972.14 @aws-sdk/credential-provider-process@3.972.13 @aws-sdk/core@3.973.15 @aws-sdk/xml-builder@3.972.8 fast-xml-parser@5.3.6
  • Introduced through: @parse/s3-files-adapter@parse-community/parse-server-s3-adapter#22cec069aafb57dd68bdbd89b5c9575e4cca801a @aws-sdk/client-s3@3.986.0 @aws-sdk/credential-provider-node@3.972.14 @aws-sdk/credential-provider-sso@3.972.13 @aws-sdk/core@3.973.15 @aws-sdk/xml-builder@3.972.8 fast-xml-parser@5.3.6
  • Introduced through: @parse/s3-files-adapter@parse-community/parse-server-s3-adapter#22cec069aafb57dd68bdbd89b5c9575e4cca801a @aws-sdk/client-s3@3.986.0 @aws-sdk/credential-provider-node@3.972.14 @aws-sdk/credential-provider-web-identity@3.972.13 @aws-sdk/core@3.973.15 @aws-sdk/xml-builder@3.972.8 fast-xml-parser@5.3.6
  • Introduced through: @parse/s3-files-adapter@parse-community/parse-server-s3-adapter#22cec069aafb57dd68bdbd89b5c9575e4cca801a @aws-sdk/client-s3@3.986.0 @aws-sdk/credential-provider-node@3.972.14 @aws-sdk/credential-provider-ini@3.972.13 @aws-sdk/core@3.973.15 @aws-sdk/xml-builder@3.972.8 fast-xml-parser@5.3.6
  • Introduced through: @parse/s3-files-adapter@parse-community/parse-server-s3-adapter#22cec069aafb57dd68bdbd89b5c9575e4cca801a @aws-sdk/client-s3@3.986.0 @aws-sdk/signature-v4-multi-region@3.986.0 @aws-sdk/middleware-sdk-s3@3.972.15 @aws-sdk/core@3.973.15 @aws-sdk/xml-builder@3.972.8 fast-xml-parser@5.3.6
  • Introduced through: @parse/s3-files-adapter@parse-community/parse-server-s3-adapter#22cec069aafb57dd68bdbd89b5c9575e4cca801a @aws-sdk/s3-request-presigner@3.989.0 @aws-sdk/signature-v4-multi-region@3.989.0 @aws-sdk/middleware-sdk-s3@3.972.15 @aws-sdk/core@3.973.15 @aws-sdk/xml-builder@3.972.8 fast-xml-parser@5.3.6
  • Introduced through: @parse/s3-files-adapter@parse-community/parse-server-s3-adapter#22cec069aafb57dd68bdbd89b5c9575e4cca801a @aws-sdk/client-s3@3.986.0 @aws-sdk/credential-provider-node@3.972.14 @aws-sdk/credential-provider-ini@3.972.13 @aws-sdk/credential-provider-env@3.972.13 @aws-sdk/core@3.973.15 @aws-sdk/xml-builder@3.972.8 fast-xml-parser@5.3.6
  • Introduced through: @parse/s3-files-adapter@parse-community/parse-server-s3-adapter#22cec069aafb57dd68bdbd89b5c9575e4cca801a @aws-sdk/client-s3@3.986.0 @aws-sdk/credential-provider-node@3.972.14 @aws-sdk/credential-provider-ini@3.972.13 @aws-sdk/credential-provider-http@3.972.15 @aws-sdk/core@3.973.15 @aws-sdk/xml-builder@3.972.8 fast-xml-parser@5.3.6
  • Introduced through: @parse/s3-files-adapter@parse-community/parse-server-s3-adapter#22cec069aafb57dd68bdbd89b5c9575e4cca801a @aws-sdk/client-s3@3.986.0 @aws-sdk/credential-provider-node@3.972.14 @aws-sdk/credential-provider-sso@3.972.13 @aws-sdk/nested-clients@3.996.3 @aws-sdk/core@3.973.15 @aws-sdk/xml-builder@3.972.8 fast-xml-parser@5.3.6
  • Introduced through: @parse/s3-files-adapter@parse-community/parse-server-s3-adapter#22cec069aafb57dd68bdbd89b5c9575e4cca801a @aws-sdk/client-s3@3.986.0 @aws-sdk/credential-provider-node@3.972.14 @aws-sdk/credential-provider-web-identity@3.972.13 @aws-sdk/nested-clients@3.996.3 @aws-sdk/core@3.973.15 @aws-sdk/xml-builder@3.972.8 fast-xml-parser@5.3.6
  • Introduced through: @parse/s3-files-adapter@parse-community/parse-server-s3-adapter#22cec069aafb57dd68bdbd89b5c9575e4cca801a @aws-sdk/client-s3@3.986.0 @aws-sdk/credential-provider-node@3.972.14 @aws-sdk/credential-provider-ini@3.972.13 @aws-sdk/nested-clients@3.996.3 @aws-sdk/core@3.973.15 @aws-sdk/xml-builder@3.972.8 fast-xml-parser@5.3.6
  • Introduced through: @parse/s3-files-adapter@parse-community/parse-server-s3-adapter#22cec069aafb57dd68bdbd89b5c9575e4cca801a @aws-sdk/client-s3@3.986.0 @aws-sdk/credential-provider-node@3.972.14 @aws-sdk/credential-provider-ini@3.972.13 @aws-sdk/credential-provider-login@3.972.13 @aws-sdk/core@3.973.15 @aws-sdk/xml-builder@3.972.8 fast-xml-parser@5.3.6
  • Introduced through: @parse/s3-files-adapter@parse-community/parse-server-s3-adapter#22cec069aafb57dd68bdbd89b5c9575e4cca801a @aws-sdk/client-s3@3.986.0 @aws-sdk/credential-provider-node@3.972.14 @aws-sdk/credential-provider-ini@3.972.13 @aws-sdk/credential-provider-process@3.972.13 @aws-sdk/core@3.973.15 @aws-sdk/xml-builder@3.972.8 fast-xml-parser@5.3.6
  • Introduced through: @parse/s3-files-adapter@parse-community/parse-server-s3-adapter#22cec069aafb57dd68bdbd89b5c9575e4cca801a @aws-sdk/client-s3@3.986.0 @aws-sdk/credential-provider-node@3.972.14 @aws-sdk/credential-provider-sso@3.972.13 @aws-sdk/token-providers@3.999.0 @aws-sdk/core@3.973.15 @aws-sdk/xml-builder@3.972.8 fast-xml-parser@5.3.6
  • Introduced through: @parse/s3-files-adapter@parse-community/parse-server-s3-adapter#22cec069aafb57dd68bdbd89b5c9575e4cca801a @aws-sdk/client-s3@3.986.0 @aws-sdk/credential-provider-node@3.972.14 @aws-sdk/credential-provider-ini@3.972.13 @aws-sdk/credential-provider-sso@3.972.13 @aws-sdk/core@3.973.15 @aws-sdk/xml-builder@3.972.8 fast-xml-parser@5.3.6
  • Introduced through: @parse/s3-files-adapter@parse-community/parse-server-s3-adapter#22cec069aafb57dd68bdbd89b5c9575e4cca801a @aws-sdk/client-s3@3.986.0 @aws-sdk/credential-provider-node@3.972.14 @aws-sdk/credential-provider-ini@3.972.13 @aws-sdk/credential-provider-web-identity@3.972.13 @aws-sdk/core@3.973.15 @aws-sdk/xml-builder@3.972.8 fast-xml-parser@5.3.6
  • Introduced through: @parse/s3-files-adapter@parse-community/parse-server-s3-adapter#22cec069aafb57dd68bdbd89b5c9575e4cca801a @aws-sdk/client-s3@3.986.0 @aws-sdk/credential-provider-node@3.972.14 @aws-sdk/credential-provider-sso@3.972.13 @aws-sdk/nested-clients@3.996.3 @aws-sdk/middleware-user-agent@3.972.15 @aws-sdk/core@3.973.15 @aws-sdk/xml-builder@3.972.8 fast-xml-parser@5.3.6
  • Introduced through: @parse/s3-files-adapter@parse-community/parse-server-s3-adapter#22cec069aafb57dd68bdbd89b5c9575e4cca801a @aws-sdk/client-s3@3.986.0 @aws-sdk/credential-provider-node@3.972.14 @aws-sdk/credential-provider-web-identity@3.972.13 @aws-sdk/nested-clients@3.996.3 @aws-sdk/middleware-user-agent@3.972.15 @aws-sdk/core@3.973.15 @aws-sdk/xml-builder@3.972.8 fast-xml-parser@5.3.6
  • Introduced through: @parse/s3-files-adapter@parse-community/parse-server-s3-adapter#22cec069aafb57dd68bdbd89b5c9575e4cca801a @aws-sdk/client-s3@3.986.0 @aws-sdk/credential-provider-node@3.972.14 @aws-sdk/credential-provider-ini@3.972.13 @aws-sdk/nested-clients@3.996.3 @aws-sdk/middleware-user-agent@3.972.15 @aws-sdk/core@3.973.15 @aws-sdk/xml-builder@3.972.8 fast-xml-parser@5.3.6
  • Introduced through: @parse/s3-files-adapter@parse-community/parse-server-s3-adapter#22cec069aafb57dd68bdbd89b5c9575e4cca801a @aws-sdk/client-s3@3.986.0 @aws-sdk/credential-provider-node@3.972.14 @aws-sdk/credential-provider-ini@3.972.13 @aws-sdk/credential-provider-login@3.972.13 @aws-sdk/nested-clients@3.996.3 @aws-sdk/core@3.973.15 @aws-sdk/xml-builder@3.972.8 fast-xml-parser@5.3.6
  • Introduced through: @parse/s3-files-adapter@parse-community/parse-server-s3-adapter#22cec069aafb57dd68bdbd89b5c9575e4cca801a @aws-sdk/client-s3@3.986.0 @aws-sdk/credential-provider-node@3.972.14 @aws-sdk/credential-provider-sso@3.972.13 @aws-sdk/token-providers@3.999.0 @aws-sdk/nested-clients@3.996.3 @aws-sdk/core@3.973.15 @aws-sdk/xml-builder@3.972.8 fast-xml-parser@5.3.6
  • Introduced through: @parse/s3-files-adapter@parse-community/parse-server-s3-adapter#22cec069aafb57dd68bdbd89b5c9575e4cca801a @aws-sdk/client-s3@3.986.0 @aws-sdk/credential-provider-node@3.972.14 @aws-sdk/credential-provider-ini@3.972.13 @aws-sdk/credential-provider-sso@3.972.13 @aws-sdk/nested-clients@3.996.3 @aws-sdk/core@3.973.15 @aws-sdk/xml-builder@3.972.8 fast-xml-parser@5.3.6
  • Introduced through: @parse/s3-files-adapter@parse-community/parse-server-s3-adapter#22cec069aafb57dd68bdbd89b5c9575e4cca801a @aws-sdk/client-s3@3.986.0 @aws-sdk/credential-provider-node@3.972.14 @aws-sdk/credential-provider-ini@3.972.13 @aws-sdk/credential-provider-web-identity@3.972.13 @aws-sdk/nested-clients@3.996.3 @aws-sdk/core@3.973.15 @aws-sdk/xml-builder@3.972.8 fast-xml-parser@5.3.6
  • Introduced through: @parse/s3-files-adapter@parse-community/parse-server-s3-adapter#22cec069aafb57dd68bdbd89b5c9575e4cca801a @aws-sdk/client-s3@3.986.0 @aws-sdk/credential-provider-node@3.972.14 @aws-sdk/credential-provider-ini@3.972.13 @aws-sdk/credential-provider-sso@3.972.13 @aws-sdk/token-providers@3.999.0 @aws-sdk/core@3.973.15 @aws-sdk/xml-builder@3.972.8 fast-xml-parser@5.3.6
  • Introduced through: @parse/s3-files-adapter@parse-community/parse-server-s3-adapter#22cec069aafb57dd68bdbd89b5c9575e4cca801a @aws-sdk/client-s3@3.986.0 @aws-sdk/credential-provider-node@3.972.14 @aws-sdk/credential-provider-sso@3.972.13 @aws-sdk/nested-clients@3.996.3 @aws-sdk/util-user-agent-node@3.973.0 @aws-sdk/middleware-user-agent@3.972.15 @aws-sdk/core@3.973.15 @aws-sdk/xml-builder@3.972.8 fast-xml-parser@5.3.6
  • Introduced through: @parse/s3-files-adapter@parse-community/parse-server-s3-adapter#22cec069aafb57dd68bdbd89b5c9575e4cca801a @aws-sdk/client-s3@3.986.0 @aws-sdk/credential-provider-node@3.972.14 @aws-sdk/credential-provider-web-identity@3.972.13 @aws-sdk/nested-clients@3.996.3 @aws-sdk/util-user-agent-node@3.973.0 @aws-sdk/middleware-user-agent@3.972.15 @aws-sdk/core@3.973.15 @aws-sdk/xml-builder@3.972.8 fast-xml-parser@5.3.6
  • Introduced through: @parse/s3-files-adapter@parse-community/parse-server-s3-adapter#22cec069aafb57dd68bdbd89b5c9575e4cca801a @aws-sdk/client-s3@3.986.0 @aws-sdk/credential-provider-node@3.972.14 @aws-sdk/credential-provider-ini@3.972.13 @aws-sdk/nested-clients@3.996.3 @aws-sdk/util-user-agent-node@3.973.0 @aws-sdk/middleware-user-agent@3.972.15 @aws-sdk/core@3.973.15 @aws-sdk/xml-builder@3.972.8 fast-xml-parser@5.3.6
  • Introduced through: @parse/s3-files-adapter@parse-community/parse-server-s3-adapter#22cec069aafb57dd68bdbd89b5c9575e4cca801a @aws-sdk/client-s3@3.986.0 @aws-sdk/credential-provider-node@3.972.14 @aws-sdk/credential-provider-ini@3.972.13 @aws-sdk/credential-provider-login@3.972.13 @aws-sdk/nested-clients@3.996.3 @aws-sdk/middleware-user-agent@3.972.15 @aws-sdk/core@3.973.15 @aws-sdk/xml-builder@3.972.8 fast-xml-parser@5.3.6
  • Introduced through: @parse/s3-files-adapter@parse-community/parse-server-s3-adapter#22cec069aafb57dd68bdbd89b5c9575e4cca801a @aws-sdk/client-s3@3.986.0 @aws-sdk/credential-provider-node@3.972.14 @aws-sdk/credential-provider-sso@3.972.13 @aws-sdk/token-providers@3.999.0 @aws-sdk/nested-clients@3.996.3 @aws-sdk/middleware-user-agent@3.972.15 @aws-sdk/core@3.973.15 @aws-sdk/xml-builder@3.972.8 fast-xml-parser@5.3.6
  • Introduced through: @parse/s3-files-adapter@parse-community/parse-server-s3-adapter#22cec069aafb57dd68bdbd89b5c9575e4cca801a @aws-sdk/client-s3@3.986.0 @aws-sdk/credential-provider-node@3.972.14 @aws-sdk/credential-provider-ini@3.972.13 @aws-sdk/credential-provider-sso@3.972.13 @aws-sdk/nested-clients@3.996.3 @aws-sdk/middleware-user-agent@3.972.15 @aws-sdk/core@3.973.15 @aws-sdk/xml-builder@3.972.8 fast-xml-parser@5.3.6
  • Introduced through: @parse/s3-files-adapter@parse-community/parse-server-s3-adapter#22cec069aafb57dd68bdbd89b5c9575e4cca801a @aws-sdk/client-s3@3.986.0 @aws-sdk/credential-provider-node@3.972.14 @aws-sdk/credential-provider-ini@3.972.13 @aws-sdk/credential-provider-web-identity@3.972.13 @aws-sdk/nested-clients@3.996.3 @aws-sdk/middleware-user-agent@3.972.15 @aws-sdk/core@3.973.15 @aws-sdk/xml-builder@3.972.8 fast-xml-parser@5.3.6
  • Introduced through: @parse/s3-files-adapter@parse-community/parse-server-s3-adapter#22cec069aafb57dd68bdbd89b5c9575e4cca801a @aws-sdk/client-s3@3.986.0 @aws-sdk/credential-provider-node@3.972.14 @aws-sdk/credential-provider-ini@3.972.13 @aws-sdk/credential-provider-sso@3.972.13 @aws-sdk/token-providers@3.999.0 @aws-sdk/nested-clients@3.996.3 @aws-sdk/core@3.973.15 @aws-sdk/xml-builder@3.972.8 fast-xml-parser@5.3.6
  • Introduced through: @parse/s3-files-adapter@parse-community/parse-server-s3-adapter#22cec069aafb57dd68bdbd89b5c9575e4cca801a @aws-sdk/client-s3@3.986.0 @aws-sdk/credential-provider-node@3.972.14 @aws-sdk/credential-provider-ini@3.972.13 @aws-sdk/credential-provider-login@3.972.13 @aws-sdk/nested-clients@3.996.3 @aws-sdk/util-user-agent-node@3.973.0 @aws-sdk/middleware-user-agent@3.972.15 @aws-sdk/core@3.973.15 @aws-sdk/xml-builder@3.972.8 fast-xml-parser@5.3.6
  • Introduced through: @parse/s3-files-adapter@parse-community/parse-server-s3-adapter#22cec069aafb57dd68bdbd89b5c9575e4cca801a @aws-sdk/client-s3@3.986.0 @aws-sdk/credential-provider-node@3.972.14 @aws-sdk/credential-provider-sso@3.972.13 @aws-sdk/token-providers@3.999.0 @aws-sdk/nested-clients@3.996.3 @aws-sdk/util-user-agent-node@3.973.0 @aws-sdk/middleware-user-agent@3.972.15 @aws-sdk/core@3.973.15 @aws-sdk/xml-builder@3.972.8 fast-xml-parser@5.3.6
  • Introduced through: @parse/s3-files-adapter@parse-community/parse-server-s3-adapter#22cec069aafb57dd68bdbd89b5c9575e4cca801a @aws-sdk/client-s3@3.986.0 @aws-sdk/credential-provider-node@3.972.14 @aws-sdk/credential-provider-ini@3.972.13 @aws-sdk/credential-provider-sso@3.972.13 @aws-sdk/nested-clients@3.996.3 @aws-sdk/util-user-agent-node@3.973.0 @aws-sdk/middleware-user-agent@3.972.15 @aws-sdk/core@3.973.15 @aws-sdk/xml-builder@3.972.8 fast-xml-parser@5.3.6
  • Introduced through: @parse/s3-files-adapter@parse-community/parse-server-s3-adapter#22cec069aafb57dd68bdbd89b5c9575e4cca801a @aws-sdk/client-s3@3.986.0 @aws-sdk/credential-provider-node@3.972.14 @aws-sdk/credential-provider-ini@3.972.13 @aws-sdk/credential-provider-web-identity@3.972.13 @aws-sdk/nested-clients@3.996.3 @aws-sdk/util-user-agent-node@3.973.0 @aws-sdk/middleware-user-agent@3.972.15 @aws-sdk/core@3.973.15 @aws-sdk/xml-builder@3.972.8 fast-xml-parser@5.3.6
  • Introduced through: @parse/s3-files-adapter@parse-community/parse-server-s3-adapter#22cec069aafb57dd68bdbd89b5c9575e4cca801a @aws-sdk/client-s3@3.986.0 @aws-sdk/credential-provider-node@3.972.14 @aws-sdk/credential-provider-ini@3.972.13 @aws-sdk/credential-provider-sso@3.972.13 @aws-sdk/token-providers@3.999.0 @aws-sdk/nested-clients@3.996.3 @aws-sdk/middleware-user-agent@3.972.15 @aws-sdk/core@3.973.15 @aws-sdk/xml-builder@3.972.8 fast-xml-parser@5.3.6
  • Introduced through: @parse/s3-files-adapter@parse-community/parse-server-s3-adapter#22cec069aafb57dd68bdbd89b5c9575e4cca801a @aws-sdk/client-s3@3.986.0 @aws-sdk/credential-provider-node@3.972.14 @aws-sdk/credential-provider-ini@3.972.13 @aws-sdk/credential-provider-sso@3.972.13 @aws-sdk/token-providers@3.999.0 @aws-sdk/nested-clients@3.996.3 @aws-sdk/util-user-agent-node@3.973.0 @aws-sdk/middleware-user-agent@3.972.15 @aws-sdk/core@3.973.15 @aws-sdk/xml-builder@3.972.8 fast-xml-parser@5.3.6

Overview

fast-xml-parser is a Validate XML, Parse XML, Build XML without C/C++ based libraries

Affected versions of this package are vulnerable to Buffer Overflow via the XMLBuilder when preserveOrder:true is set. An attacker can cause the application to crash by providing specially crafted input data.

Workaround

This vulnerability can be mitigated by using preserveOrder:false or by validating input data before passing it to the builder.

Remediation

Upgrade fast-xml-parser to version 4.5.4, 5.3.8 or higher.

References