astro is vulnerable to Generation of Error Message Containing Sensitive Information
30
Low Risk
In certain situations, the Node endpoint for assets could return unintended responses. The patched versions ensure that, in production, only opaque messages (Internal Server Error) are returned to users in the event of malformed requests. Internal logs remain unaffected and will continue to provide useful information for debugging purposes.
You are affected if you are using a version that falls within the vulnerable range.
astro is vulnerable to Generation of Error Message Containing Sensitive Information in versions 3.3.0 - 3.6.4 and 4.0.0 - 4.4.6.
Upgrade the astro library to a patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant