PT-2023-26168 · Unknown · Feathersjs

Codeanio

·

Publicado

2023-07-19

·

Atualizado

2023-07-28

·

CVE-2023-37899

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Feathersjs versions prior to 4.5.18 Feathersjs versions prior to 5.0.8
Description The Feathers socket handler did not catch invalid string conversion errors, which could cause the NodeJS process to crash when sending an unexpected Socket.io message. For example, sending a message like socket.emit('find', { toString: '' }) could crash the process.
Recommendations For versions prior to 4.5.18, upgrade to version 4.5.18. For versions prior to 5.0.8, upgrade to version 5.0.8.

Exploit

Correção

Improper Check for Exceptional Conditions

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-37899
GHSA-HHR9-RH25-HVF9

Produtos afetados

Feathersjs