{ "schema_version": "1.4.0", "id": "GHSA-5w65-6875-rhq8", "modified": "2020-08-31T18:34:32Z", "published": "2019-09-11T23:01:57Z", "aliases": [], "summary": "Undefined Behavior in sailsjs-cacheman", "details": "All versions of `sailsjs-cacheman` have a vulnerability that may lead to Undefined Behavior. The config variable is exposing to the global scope which may overwrite other variables and cause the application to misbehave.\n\n\n## Recommendation\n\nNo fix is currently available. Consider using an alternative module until a fix is made available.", "severity": [], "affected": [ { "package": { "ecosystem": "npm", "name": "sailsjs-cacheman" }, "ranges": [ { "type": "ECOSYSTEM", "events": [ { "introduced": "0" }, { "last_affected": "1.0.0" } ] } ] } ], "references": [ { "type": "WEB", "url": "https://github.com/gayanhewa/sailsjs-cacheman/pull/10" }, { "type": "WEB", "url": "https://github.com/gayanhewa/sailsjs-cacheman/commit/4a456f44141ae2d5aed8cb32a82063356dcc318f" }, { "type": "WEB", "url": "https://www.npmjs.com/advisories/752" } ], "database_specific": { "cwe_ids": [], "severity": "LOW", "github_reviewed": true, "github_reviewed_at": "2019-09-03T23:31:41Z", "nvd_published_at": null } }