Description
atob 2.0.3 and earlier allocates uninitialized Buffers when number is passed in input on Node.js 4.x and below.
Remediation
References
https://hackerone.com/reports/321686
https://security.netapp.com/advisory/ntap-20230622-0009/
Related Vulnerabilities
CVE-2022-41376 Vulnerability in npm package metro4
CVE-2022-23464 Vulnerability in maven package com.nepxion:discovery-plugin-admin-center
CVE-2021-25913 Vulnerability in npm package set-or-get
CVE-2022-25898 Vulnerability in maven package org.webjars.bower:jsrsasign
CVE-2022-39386 Vulnerability in npm package @fastify/websocket