
Cloud Vulnerability DB
A community-led vulnerabilities database
The vulnerability (GHSA-g3qw-9pgp-xpj4) affects the njwt npm package, specifically versions prior to 1.0.0. This security issue was discovered and published to the GitHub Advisory Database on September 1, 2020, with the latest update on January 9, 2023. The vulnerability is classified as low severity and is identified as an out-of-bounds read vulnerability (GitHub Advisory).
The vulnerability is categorized as CWE-125 (Out-of-bounds Read) and occurs when a number is passed into the base64urlEncode function of the njwt package. The technical implementation details reveal that the vulnerability manifests differently depending on the Node.js version being used (GitHub Advisory).
The impact of this vulnerability varies based on the Node.js version in use. On Node.js 6.x or lower, the vulnerability can lead to exposure of sensitive information. For all other versions of Node.js, the vulnerability creates a potential Denial of Service condition (GitHub Advisory).
The vulnerability is triggered when a number is passed into the base64urlEncode function of the affected njwt versions. The specific exploitation method involves manipulating the input to the base64urlEncode function to cause an out-of-bounds read condition (GitHub Advisory).
The recommended mitigation is to upgrade to njwt version 1.0.0 or later, which contains the fix for this vulnerability (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."