PT-2022-3610 · Dicer · Dicer

Aras Abbasi

·

Published

2022-05-20

·

Updated

2025-05-12

·

CVE-2022-24434

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions dicer versions all
Description The issue is related to the dicer package, where a malicious attacker can send a modified form to the server, causing the Node.js service to crash. By sending the payload repeatedly, an attacker can achieve a continuous denial of service. The vulnerability is associated with incorrect resource cleanup or deallocation in the dicer parser.
Recommendations As a temporary workaround, consider disabling the vulnerable dicer package until a patch is available. Restrict access to the dicer package to minimize the risk of exploitation. Avoid using the dicer package in production environments until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Resource Release

Weakness Enumeration

Related Identifiers

BDU:2022-04395
CVE-2022-24434
GHSA-WM7H-9275-46V2
SNYK-JAVA-ORGWEBJARSNPM-2838865
SNYK-JS-DICER-2311764

Affected Products

Dicer