QID 982067
QID 982067: Nodejs (npm) Security Update for valine (GHSA-p2c4-gxp4-j3xp)
Valine 1.4.14 allows remote attackers to cause a denial of service (application outage) by supplying a ua (aka User-Agent) value that only specifies the product and version.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-p2c4-gxp4-j3xp for updates pertaining to this vulnerability.
Vendor References
- GHSA-p2c4-gxp4-j3xp -
github.com/advisories/GHSA-p2c4-gxp4-j3xp
CVEs related to QID 982067
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-p2c4-gxp4-j3xp | valine |
|