QID 982624
QID 982624: Nodejs (npm) Security Update for shiba (GHSA-jvf4-g24p-2qgw)
"All versions of package shiba are vulnerable to Arbitrary Code Execution due to the default usage of the function load() of the package js-yaml instead of its secure replacement , safeLoad()."
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-jvf4-g24p-2qgw for updates pertaining to this vulnerability.
Vendor References
- GHSA-jvf4-g24p-2qgw -
github.com/advisories/GHSA-jvf4-g24p-2qgw
CVEs related to QID 982624
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-jvf4-g24p-2qgw | shiba |
|