Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security - Medium severity - Vulnerable module: canvas@1.1.6 #69

Open
vbdata opened this issue Aug 25, 2020 · 0 comments
Open

Security - Medium severity - Vulnerable module: canvas@1.1.6 #69

vbdata opened this issue Aug 25, 2020 · 0 comments

Comments

@vbdata
Copy link

vbdata commented Aug 25, 2020

Trying to use js-imagediff from jsdeliver which complains about security issue in the package.

Js deliver download page wait some seconds and until the varning message is shown. It leads to the
Snyk report on the issue.

MEDIUM SEVERITY
Denial of Service (DoS)
Vulnerable module: canvas, Introduced through: canvas@1.1.6

Detailed paths
Introduced through: imagediff@1.0.8 › canvas@1.1.6

Remediation: Upgrade to canvas@1.6.10.

Overview
canvas is a Cairo-backed Canvas implementation for Node.js.

Affected versions of this package are vulnerable to Denial of Service (DoS). Processing malicious JPEGs or GIFs files could crash the node process.

Denial of Service (DoS) vulnerability report

Maybe just an old version on Js deliver ?
It says 1.0.8 on the Js deliver page but in the code comments it says 1.0.3

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant