HIGH7.5
GHSA-frp9-2v6r-gj97
muhammara and hummus vulnerable to null pointer dereference on bad response object
Quick fix
GHSA-frp9-2v6r-gj97 — hummus: upgrade to the fixed version with the command below.
npm install hummus@1.0.111Details
The package muhammara before 2.6.0 and the package hummus before 1.0.111 are vulnerable to Denial of Service (DoS) when PDFStreamForResponse() is used with invalid data.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2022-25885[ADVISORY]
- https://github.com/galkahana/HummusJS/issues/439[WEB]
- https://github.com/julianhille/MuhammaraJS/issues/188[WEB]
- https://github.com/galkahana/HummusJS/commit/a9bf2520ab5abb69f9328906e406fbebfb36159a[WEB]
- https://github.com/julianhille/MuhammaraJS/commit/0a6427eec82ef2978995e453de2dc0d6224dd46c[WEB]
- https://github.com/julianhille/MuhammaraJS[PACKAGE]
- https://security.snyk.io/vuln/SNYK-JS-HUMMUS-3091139[WEB]
- https://security.snyk.io/vuln/SNYK-JS-MUHAMMARA-3091137[WEB]