PT-2022-17612 · Unknown · V-Server Lite

Liran Tal

+1

·

Published

2022-12-20

·

Updated

2022-12-29

·

CVE-2022-25940

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions lite-server versions all
Description The issue arises when an attacker sends an HTTP request that includes control characters, which the decodeURI() function is unable to parse, leading to a Denial of Service (DoS). This occurs when the decodeURI() function encounters characters it cannot process, resulting in the service becoming unavailable.
Recommendations For all versions, consider disabling the decodeURI() function or restricting HTTP requests that include control characters until a patch is available. As a temporary workaround, restrict access to the HTTP endpoint to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Resource Exhaustion

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-25940
GHSA-89W7-5Q45-R53W

Affected Products

V-Server Lite