VDB
Sign up
MEDIUM4.8

GHSA-j438-45hc-vjhm

CSRF and DNS Rebinding in Oasis

Quick fix

GHSA-j438-45hc-vjhm — @fraction/oasis: upgrade to the fixed version with the command below.

npm install @fraction/oasis@2.15.0

Details

### Impact _What kind of vulnerability is it? Who is impacted?_

If you're running a vulnerable application on your computer and an attacker can trick you into visiting a malicious website, they could use [DNS rebinding](https://en.wikipedia.org/wiki/DNS_rebinding) and [CSRF](https://en.wikipedia.org/wiki/Cross-site_request_forgery) attacks to read/write to vulnerable applications.

**There is no evidence that suggests that this has been used in the wild.**

### Patches _Has the problem been patched? What versions should users upgrade to?_

Yes, 2.15.0.

### Workarounds _Is there a way for users to fix or remediate the vulnerability without upgrading?_

No.

### References _Are there any links users can visit to find out more?_

No.

### For more information If you have any questions or comments about this advisory: * Open an issue in [fraction/oasis](http://github.com/fraction/oasis) * Email me at [christianbundy@fraction.io](mailto:christianbundy@fraction.io)

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@fraction/oasis
Introduced in: 0Fixed in: 2.15.0
Fixnpm install @fraction/oasis@2.15.0

References