VDB
Sign up
LOW

GHSA-g3qw-9pgp-xpj4

Out-of-bounds Read in njwt

Quick fix

GHSA-g3qw-9pgp-xpj4 — njwt: upgrade to the fixed version with the command below.

npm install njwt@1.0.0

Details

Versions of `njwt` prior to 1.0.0 are vulnerable to out-of-bounds reads when a number is passed into the `base64urlEncode` function.

On Node.js 6.x or lower this can expose sensitive information and on any other version of Node.js this creates a Denial of Service vulnerability.

## Recommendation

Upgrade to version 1.0.0.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/njwt
Introduced in: 0Fixed in: 1.0.0
Fixnpm install njwt@1.0.0

References