Description
atob 2.0.3 and earlier allocates uninitialized Buffers when number is passed in input on Node.js 4.x and below.
Remediation
References
https://hackerone.com/reports/321686
https://security.netapp.com/advisory/ntap-20230622-0009/
Related Vulnerabilities
CVE-2022-23812 Vulnerability in npm package node-ipc
CVE-2020-28052 Vulnerability in maven package org.bouncycastle:bcprov-jdk15to18
CVE-2020-8205 Vulnerability in npm package @uppy/companion
CVE-2020-36186 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2020-28282 Vulnerability in maven package org.webjars.npm:getobject