You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
This repository was archived by the owner on Dec 1, 2020. It is now read-only.
Path to vulnerable library: /tmp/git/instabyte/node_modules/js-yaml/package.json
Dependency Hierarchy:
jest-expo-26.0.0.tgz (Root Library)
jest-22.4.3.tgz
jest-cli-22.4.3.tgz
istanbul-api-1.3.1.tgz
❌ js-yaml-3.11.0.tgz (Vulnerable Library)
Vulnerability Details
Versions js-yaml prior to 3.13.0 are vulnerable to Denial of Service. By parsing a carefully-crafted YAML file, the node process stalls and may exhaust system resources leading to a Denial of Service.