Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6663-c963-2gqg

Опубликовано: 18 фев. 2019
Источник: github
Github: Прошло ревью

Описание

DoS due to excessively large websocket message in ws

Affected versions of ws do not appropriately limit the size of incoming websocket payloads, which may result in a denial of service condition when the node process crashes after receiving a large payload.

Recommendation

Update to version 1.1.1 or later. Alternatively, set the maxpayload option for the ws server to a value smaller than 256MB.

Пакеты

Наименование

ws

npm
Затронутые версииВерсия исправления

< 1.1.1

1.1.1

EPSS

Процентиль: 98%
0.66075
Средний

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 7 лет назад

ws is a "simple to use, blazing fast and thoroughly tested websocket client, server and console for node.js, up-to-date against RFC-6455". By sending an overly long websocket payload to a `ws` server, it is possible to crash the node process. This affects ws 1.1.0 and earlier.

CVSS3: 7.5
nvd
больше 7 лет назад

ws is a "simple to use, blazing fast and thoroughly tested websocket client, server and console for node.js, up-to-date against RFC-6455". By sending an overly long websocket payload to a `ws` server, it is possible to crash the node process. This affects ws 1.1.0 and earlier.

CVSS3: 7.5
debian
больше 7 лет назад

ws is a "simple to use, blazing fast and thoroughly tested websocket c ...

EPSS

Процентиль: 98%
0.66075
Средний

Дефекты

CWE-400