LOW
GHSA-g3qw-9pgp-xpj4
Out-of-bounds Read in njwt
Quick fix
GHSA-g3qw-9pgp-xpj4 — njwt: upgrade to the fixed version with the command below.
npm install njwt@1.0.0Details
Versions of `njwt` prior to 1.0.0 are vulnerable to out-of-bounds reads when a number is passed into the `base64urlEncode` function.
On Node.js 6.x or lower this can expose sensitive information and on any other version of Node.js this creates a Denial of Service vulnerability.
## Recommendation
Upgrade to version 1.0.0.
Are you affected?
Enter the version of the package you're using.