Description
atob 2.0.3 and earlier allocates uninitialized Buffers when number is passed in input on Node.js 4.x and below.
Remediation
References
https://hackerone.com/reports/321686
https://security.netapp.com/advisory/ntap-20230622-0009/
Related Vulnerabilities
CVE-2023-22474 Vulnerability in npm package parse-server
CVE-2022-41915 Vulnerability in maven package io.netty:netty-codec
CVE-2017-16037 Vulnerability in npm package gomeplus-h5-proxy
CVE-2021-32859 Vulnerability in maven package org.webjars.npm:github-com-baremetrics-calendar
CVE-2021-21625 Vulnerability in maven package org.jenkins-ci.plugins:aws-credentials