Skip to content

Snyk UUID vulnerability #355

@CoreyCWeb

Description

@CoreyCWeb

https://security.snyk.io/vuln/SNYK-JS-UUID-16133035

Affecting uuid package, versions <11.1.1>=12.0.0 <14.0.0

Upgrade uuid to version 11.1.1, 14.0.0 or higher.

Overview
uuid is a RFC4122 (v1, v4, and v5) compliant UUID library.

Affected versions of this package are vulnerable to Improper Validation of Specified Index, Position, or Offset in Input due to accepting external output buffers but not rejecting out-of-range writes (small buf or large offset). This inconsistency allows silent partial writes into caller-provided buffers.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions