Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-27wq-qx3q-fxm9

Опубликовано: 23 авг. 2021
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Improper Handling of Unexpected Data Type in ced

Impact

In ced v0.1.0, passing data types other than Buffer causes the Node.js process to crash.

Patches

The problem has been patched in ced v1.0.0. You can upgrade from v0.1.0 without any breaking changes.

Workarounds

Before passing an argument to ced, verify it’s a Buffer using Buffer.isBuffer(obj).

CVSS score

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/RL:O/RC:C

Base Score: 7.5 (High) Temporal Score: 7.2 (High)

Since ced is a library, the scoring is based on the “reasonable worst-case implementation scenario”, namely, accepting data from untrusted sources over a network and passing it directly to ced. Depending on your specific implementation, the vulnerability’s severity in your program may be different.

Proof of concept

const express = require("express"); const bodyParser = require("body-parser"); const ced = require("ced"); const app = express(); app.use(bodyParser.raw()); app.post("/", (req, res) => { const encoding = ced(req.body); res.end(encoding); }); app.listen(3000);

curl --request POST --header "Content-Type: text/plain" --data foo http://localhost:3000 crashes the server.

References

Пакеты

Наименование

ced

npm
Затронутые версииВерсия исправления

< 1.0.0

1.0.0

EPSS

Процентиль: 63%
0.00446
Низкий

7.5 High

CVSS3

Дефекты

CWE-241

Связанные уязвимости

CVSS3: 7.5
nvd
около 4 лет назад

ced detects character encoding using Google’s compact_enc_det library. In ced v0.1.0, passing data types other than `Buffer` causes the Node.js process to crash. The problem has been patched in ced v1.0.0. As a workaround, before passing an argument to ced, verify it’s a `Buffer` using `Buffer.isBuffer(obj)`.

EPSS

Процентиль: 63%
0.00446
Низкий

7.5 High

CVSS3

Дефекты

CWE-241