4.5.2
9 years ago
29 days ago
Known vulnerabilities in the nuxt package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
Affected versions of this package are vulnerable to Information Exposure via the Chrome DevTools workspace endpoint when the development server is bound to a network-reachable interface and How to fix Information Exposure? Upgrade | >=3.21.7 <3.21.10>=4.4.7 <4.5.1 |
Affected versions of this package are vulnerable to Incorrect Authorization in the route rule matching. An attacker can gain unauthorized access to protected pages and sensitive data by crafting requests to mixed-case paths that bypass authentication middleware. How to fix Incorrect Authorization? Upgrade | >=3.21.7 <3.21.10>=4.4.7 <4.5.1 |
Affected versions of this package are vulnerable to Improper Validation of Specified Quantity in Input via the How to fix Improper Validation of Specified Quantity in Input? Upgrade | >=3.1.0 <3.21.10>=4.0.0 <4.5.1 |
Affected versions of this package are vulnerable to Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') via the Note: This is only exploitable if a server island component forwards untrusted input into a dynamic component path, either explicitly or via attribute fallthrough when the island's root is a polymorphic component. How to fix Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')? Upgrade | >=3.1.0 <3.21.10>=4.0.0 <4.5.1 |
Affected versions of this package are vulnerable to Arbitrary Code Injection via the Note: This is only exploitable if How to fix Arbitrary Code Injection? Upgrade | >=3.4.0 <3.21.10>=4.0.0 <4.5.1 |
Affected versions of this package are vulnerable to Allocation of Resources Without Limits or Throttling via the Note: This is only exploitable if the server is accessible to unauthenticated users and does not enforce request body size or nesting depth limits. How to fix Allocation of Resources Without Limits or Throttling? Upgrade | >=3.1.0 <3.21.10>=4.0.0 <4.5.1 |