Description
A buffer overflow is present in canvas version <= 1.6.9, which could lead to a Denial of Service or execution of arbitrary code when it processes a user-provided image.
Remediation
References
https://hackerone.com/reports/315037
Related Vulnerabilities
CVE-2021-23346 Vulnerability in maven package org.webjars.npm:html-parse-stringify2
CVE-2020-6468 Vulnerability in maven package org.webjars.npm:electron
CVE-2016-3088 Vulnerability in maven package org.apache.activemq:apache-activemq
CVE-2020-2211 Vulnerability in maven package com.elasticbox.jenkins-ci.plugins:kubernetes-ci
CVE-2019-19919 Vulnerability in maven package li.rudin.mavenjs:handlebars