6.4.0
7 years ago
7 years ago
Known vulnerabilities in the org.webjars.npm:pg package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
org.webjars.npm:pg is a non-blocking PostgreSQL client for node.js. Affected versions of this package are vulnerable to Arbitrary Code Execution. When parsing results of a query, it goes through a form of PoC:
How to fix Arbitrary Code Execution? There is no fixed version for | [0,) |