GHSA-j438-45hc-vjhm
CSRF and DNS Rebinding in Oasis
Quick fix
GHSA-j438-45hc-vjhm — @fraction/oasis: upgrade to the fixed version with the command below.
npm install @fraction/oasis@2.15.0Details
### Impact _What kind of vulnerability is it? Who is impacted?_
If you're running a vulnerable application on your computer and an attacker can trick you into visiting a malicious website, they could use [DNS rebinding](https://en.wikipedia.org/wiki/DNS_rebinding) and [CSRF](https://en.wikipedia.org/wiki/Cross-site_request_forgery) attacks to read/write to vulnerable applications.
**There is no evidence that suggests that this has been used in the wild.**
### Patches _Has the problem been patched? What versions should users upgrade to?_
Yes, 2.15.0.
### Workarounds _Is there a way for users to fix or remediate the vulnerability without upgrading?_
No.
### References _Are there any links users can visit to find out more?_
No.
### For more information If you have any questions or comments about this advisory: * Open an issue in [fraction/oasis](http://github.com/fraction/oasis) * Email me at [christianbundy@fraction.io](mailto:christianbundy@fraction.io)
Are you affected?
Enter the version of the package you're using.