deis@0.0.5 vulnerabilities

Command-line Client for Deis, the open PaaS

  • latest version

    1.9.1

  • latest non vulnerable version

  • first published

    11 years ago

  • latest version published

    9 years ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the deis package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • L
    Man-in-the-Middle (MitM)

    deis is a command-line Client for Deis, the open PaaS.

    Affected versions of this package are vulnerable to Man-in-the-Middle (MitM). The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, aka the "POODLE" issue.

    [,1.4)