PT-2020-20016 · Fastify · Fastify
Published
2020-07-30
·
Updated
2020-08-06
·
CVE-2020-8192
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Fastify versions 2.14.1 and 3.0.0-rc.4
Description
A denial of service issue exists that allows a malicious user to trigger resource exhaustion with specially crafted schemas when the
allErrors option is used.Recommendations
For Fastify version 2.14.1, consider disabling the
allErrors option as a temporary workaround until a patch is available.
For Fastify version 3.0.0-rc.4, consider disabling the allErrors option as a temporary workaround until a patch is available.Exploit
Fix
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fastify