{"id":"GHSA-j438-45hc-vjhm","summary":"CSRF and DNS Rebinding in Oasis","details":"### Impact\n_What kind of vulnerability is it? Who is impacted?_\n\nIf you're running a vulnerable application on your computer and an attacker can trick you into visiting a malicious website, they could use [DNS rebinding](https://en.wikipedia.org/wiki/DNS_rebinding) and [CSRF](https://en.wikipedia.org/wiki/Cross-site_request_forgery) attacks to read/write to vulnerable applications. \n\n**There is no evidence that suggests that this has been used in the wild.**\n\n### Patches\n_Has the problem been patched? What versions should users upgrade to?_\n\nYes, 2.15.0.\n\n### Workarounds\n_Is there a way for users to fix or remediate the vulnerability without upgrading?_\n\nNo.\n\n### References\n_Are there any links users can visit to find out more?_\n\nNo.\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Open an issue in [fraction/oasis](http://github.com/fraction/oasis)\n* Email me at [christianbundy@fraction.io](mailto:christianbundy@fraction.io)","aliases":["CVE-2020-11003"],"modified":"2026-09-10T03:48:44.035056868Z","published":"2020-04-16T03:14:39Z","database_specific":{"nvd_published_at":null,"cwe_ids":["CWE-352"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2020-04-15T22:57:22Z"},"references":[{"type":"WEB","url":"https://github.com/fraction/oasis/security/advisories/GHSA-j438-45hc-vjhm"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-11003"}],"affected":[{"package":{"name":"@fraction/oasis","ecosystem":"npm","purl":"pkg:npm/%40fraction/oasis"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"2.15.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/04/GHSA-j438-45hc-vjhm/GHSA-j438-45hc-vjhm.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N"}]}