7.8.0
11 years ago
2 months ago
Known vulnerabilities in the thumbor package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
thumbor is a thumbor is an open-source photo thumbnail service by globo.com Affected versions of this package are vulnerable to Directory Traversal via the How to fix Directory Traversal? Upgrade | [,7.8.0) |
thumbor is a thumbor is an open-source photo thumbnail service by globo.com Affected versions of this package are vulnerable to Regular Expression Denial of Service (ReDoS) in the How to fix Regular Expression Denial of Service (ReDoS)? Upgrade | [,7.8.0) |
thumbor is a thumbor is an open-source photo thumbnail service by globo.com Affected versions of this package are vulnerable to Denial of Service (DoS) via the How to fix Denial of Service (DoS)? Upgrade | [,7.8.0) |
thumbor is a thumbor is an open-source photo thumbnail service by globo.com Affected versions of this package are vulnerable to Improper Verification of Cryptographic Signature via the URL signature removal process. An attacker can manipulate the validated URL and bypass intended access controls by injecting additional signature substrings into the request path, resulting in the loading of resources from unauthorized domains or paths. How to fix Improper Verification of Cryptographic Signature? Upgrade | [,7.8.0) |
thumbor is a thumbor is an open-source photo thumbnail service by globo.com Affected versions of this package are vulnerable to Regular Expression Denial of Service (ReDoS) via the How to fix Regular Expression Denial of Service (ReDoS)? Upgrade | [,7.8.0) |
thumbor is a thumbor is an open-source photo thumbnail service by globo.com Affected versions of this package are vulnerable to Division by zero via the How to fix Division by zero? Upgrade | [,7.8.0) |