Description
atob 2.0.3 and earlier allocates uninitialized Buffers when number is passed in input on Node.js 4.x and below.
Remediation
References
https://hackerone.com/reports/321686
https://security.netapp.com/advisory/ntap-20230622-0009/
Related Vulnerabilities
CVE-2021-23346 Vulnerability in npm package html-parse-stringify2
CVE-2023-38286 Vulnerability in maven package org.thymeleaf:thymeleaf
CVE-2021-23346 Vulnerability in maven package org.webjars.npm:html-parse-stringify2
CVE-2020-13128 Vulnerability in maven package com.googlecode.gwtupload:gwtupload
CVE-2022-25927 Vulnerability in maven package org.webjars.npm:github-com-faisalman-ua-parser-js