QID 983944
QID 983944: Nodejs (npm) Security Update for memjs (GHSA-cx8m-8xmx-q8v3)
Versions of `memjs` prior to 1.2.2 are vulnerable to Denial of Service (DoS). The package fails to sanitize the `value` option passed to the Buffer constructor, which may allow attackers to pass large values exhausting system resources. ## Recommendation Upgrade to version 1.2.2 or later.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-cx8m-8xmx-q8v3 for updates pertaining to this vulnerability.
Vendor References
- GHSA-cx8m-8xmx-q8v3 -
github.com/advisories/GHSA-cx8m-8xmx-q8v3
CVEs related to QID 983944
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-cx8m-8xmx-q8v3 | memjs |
|