
We found results for “”
WS-2018-0148
Good to know:

Date: January 16, 2018
The `utile` npm module, version 0.3.0, allows to extract sensitive data from uninitialized memory or to cause a DoS by passing in a large number, in setups where typed user input can be passed (e.g. from JSON).
Language: Java
Severity Score
Related Resources (2)
Severity Score
Weakness Type (CWE)
Improper Initialization
CWE-665Top Fix

Upgrade Version
Upgrade to version seidemann-web/wave-theme - no_fix;seidemann-web/wave-theme - dev-fixUpLanguageConstants;seidemann-web/wave-theme - dev-omage-theme;seidemann-web/wave-theme - dev-WT-36/Sticky-Header-Fixes;limefamily/yii2-limetheme - 1.0.12;utile - no_fix;azure-cli - no_fix;dreamfactory/df-api-docs-ui - 1.1.0;JetBrains.Rider.Frontend5 - 213.0.20211008.154703-eap03;lukesnowden/application-base - no_fix;oxid-esales/wave-theme - dev-oxscript-google-analytics;myVisasNodeJs - no_fix;Ncapsulate.Karma - no_fix;ristorantino/aditions - dev-master-ko-js-update;JetBrains.Rider.Frontend6 - no_fix;org.webjars.npm:utile:no_fix
CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | NONE |
User Interaction (UI): | NONE |
Scope (S): | UNCHANGED |
Confidentiality (C): | NONE |
Integrity (I): | NONE |
Availability (A): | HIGH |