lob is vulnerable to Path Traversal
65
Medium Risk
Affected versions of this package are vulnerable to a high-severity path traversal issue in the _transmit function in resourceBase.js, because the uri parameter is not properly sanitized and could be manipulated to access unintended API endpoints. This patch also replaces the deprecated request package with axios to resolve a security vulnerability.
You are affected if you are using a version that falls within the vulnerable range.
lob is vulnerable to Path Traversal in versions 1.0.0 - 7.0.1.
Upgrade the lob library to the patch version.
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant