Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-42xw-2xvc-qx8m

Опубликовано: 29 мая 2019
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Denial of Service in axios

Versions of axios prior to 0.18.1 are vulnerable to Denial of Service. If a request exceeds the maxContentLength property, the package prints an error but does not stop the request. This may cause high CPU usage and lead to Denial of Service.

Recommendation

Upgrade to 0.18.1 or later.

Пакеты

Наименование

axios

npm
Затронутые версииВерсия исправления

<= 0.18.0

0.18.1

EPSS

Процентиль: 94%
0.1374
Средний

7.5 High

CVSS3

Дефекты

CWE-20
CWE-755

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 7 лет назад

Axios up to and including 0.18.0 allows attackers to cause a denial of service (application crash) by continuing to accepting content after maxContentLength is exceeded.

CVSS3: 7.5
nvd
почти 7 лет назад

Axios up to and including 0.18.0 allows attackers to cause a denial of service (application crash) by continuing to accepting content after maxContentLength is exceeded.

CVSS3: 7.5
debian
почти 7 лет назад

Axios up to and including 0.18.0 allows attackers to cause a denial of ...

EPSS

Процентиль: 94%
0.1374
Средний

7.5 High

CVSS3

Дефекты

CWE-20
CWE-755