First published: Sat May 16 2020(Updated: )
A flaw was found in nodejs-stringstream. Node.js stringstream module is vulnerable to an out-of-bounds read because of allocation of uninitialized buffers when a number is passed in the input stream.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/nodejs-stringstream | <0.0.6 | 0.0.6 |
Langgenius Dify Node.js | <0.0.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-21270 is classified as a moderate severity vulnerability due to the potential for an out-of-bounds read.
To fix CVE-2018-21270, upgrade the nodejs-stringstream module to version 0.0.6 or later.
Versions of the nodejs-stringstream module prior to 0.0.6 are affected by CVE-2018-21270.
Yes, CVE-2018-21270 specifically affects the nodejs-stringstream module used within Node.js.
CVE-2018-21270 is an out-of-bounds read vulnerability caused by the allocation of uninitialized buffers.