nats.ws@1.0.0-104 vulnerabilities

WebSocket NATS client

  • latest version

    1.29.2

  • latest non vulnerable version

  • first published

    4 years ago

  • latest version published

    4 months ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the nats.ws package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Information Exposure

    nats.ws is a WebSocket NATS client

    Affected versions of this package are vulnerable to Information Exposure. NATS nats.js before 2.0.0-209, nats.ws before 1.0.0-111, and nats.deno before 1.0.0-9 allow credential disclosure from a client to a server.

    How to fix Information Exposure?

    Upgrade nats.ws to version 1.0.0-111 or higher.

    <1.0.0-111