QID 983845
QID 983845: Nodejs (npm) Security Update for @fraction/oasis (GHSA-j438-45hc-vjhm)
Security update has been released for @fraction/oasis to fix the vulnerability. Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
_What kind of vulnerability is it? Who is impacted?_ If you're running a vulnerable application on your computer and an attacker can trick you into visiting a malicious website, they could use [DNS rebinding](https://en.wikipedia.org/wiki/DNS_rebinding) and [CSRF](https://en.wikipedia.org/wiki/Cross-site_request_forgery) attacks to read/write to vulnerable applications. **There is no evidence that suggests that this has been used in the wild.**
Solution
_Has the problem been patched? What versions should users upgrade to?_
Yes, 2.15.0.Workaround:
_Is there a way for users to fix or remediate the vulnerability without upgrading?_ No.
_Is there a way for users to fix or remediate the vulnerability without upgrading?_ No.
Vendor References
- GHSA-j438-45hc-vjhm -
github.com/advisories/GHSA-j438-45hc-vjhm
CVEs related to QID 983845
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-j438-45hc-vjhm | @fraction/oasis |
|