js-yaml@3.4.5 vulnerabilities
YAML 1.2 parser and serializer
-
latest version
4.1.0
-
latest non vulnerable version
-
first published
13 years ago
-
latest version published
4 years ago
-
licenses detected
- >=0
Direct Vulnerabilities
Known vulnerabilities in the js-yaml package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.Vulnerability | Vulnerable Version |
---|---|
js-yaml is a human-friendly data serialization language. Affected versions of this package are vulnerable to Arbitrary Code Execution. When an object with an executable How to fix Arbitrary Code Execution? Upgrade |
<3.13.1
|
js-yaml is a human-friendly data serialization language. Affected versions of this package are vulnerable to Denial of Service (DoS). The parsing of a specially crafted YAML file may exhaust the system resources. How to fix Denial of Service (DoS)? Upgrade |
>=3.0.0 <3.13.0
|