{"id":"GHSA-83rx-c8cr-6j8q","summary":"Insecure Default Configuration in tesseract.js","details":"Versions of `tesseract.js` prior to 1.0.19 default to using a third-party proxy.  Requests may be proxied through `crossorigin.me` which clearly states is not suitable for production use. This may lead to instability and privacy violations.\n\n\n## Recommendation\n\nUpgrade to version 1.0.19 or later.","modified":"2021-08-04T21:33:58Z","published":"2019-06-05T20:48:55Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2019-06-05T20:48:43Z","nvd_published_at":null,"cwe_ids":["CWE-829"],"severity":"MODERATE"},"references":[{"type":"WEB","url":"https://github.com/naptha/tesseract.js/pull/267"},{"type":"WEB","url":"https://github.com/naptha/tesseract.js/commit/679eba055f2a4271558e86beec3d1b70cae3fb28"},{"type":"WEB","url":"https://snyk.io/vuln/SNYK-JS-TESSERACTJS-174085"},{"type":"WEB","url":"https://www.npmjs.com/advisories/792"}],"affected":[{"package":{"name":"tesseract.js","ecosystem":"npm","purl":"pkg:npm/tesseract.js"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.0.19"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/06/GHSA-83rx-c8cr-6j8q/GHSA-83rx-c8cr-6j8q.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}