VDB
Sign up
HIGH7.5

GHSA-xxc2-j7jj-6g5m

Raneto Denial of Service via crafted payload injected into `Search` parameter

Quick fix

GHSA-xxc2-j7jj-6g5m — raneto: upgrade to the fixed version with the command below.

npm install raneto@0.17.1

Details

An issue in Renato v0.17.0 allows attackers to cause a Denial of Service (DoS) via a crafted payload injected into the `Search` parameter.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/raneto
Introduced in: 0Fixed in: 0.17.1
Fixnpm install raneto@0.17.1

References