Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8225-6cvr-8pqp

Опубликовано: 09 авг. 2018
Источник: github
Github: Прошло ревью
CVSS3: 5.9

Описание

superagent vulnerable to zip bomb attacks

Affected versions of superagent do not check the post-decompression size of ZIP compressed HTTP responses prior to decompressing. This results in the package being vulnerable to a ZIP bomb attack, where an extremely small ZIP file becomes many orders of magnitude larger when decompressed.

This may result in unrestrained CPU/Memory/Disk consumption, causing a denial of service condition.

Recommendation

Update to version 3.7.0 or later.

Пакеты

Наименование

superagent

npm
Затронутые версииВерсия исправления

< 3.7.0

3.7.0

EPSS

Процентиль: 59%
0.00385
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-400
CWE-409

Связанные уязвимости

CVSS3: 5.9
ubuntu
больше 7 лет назад

The HTTP client module superagent is vulnerable to ZIP bomb attacks. In a ZIP bomb attack, the HTTP server replies with a compressed response that becomes several magnitudes larger once uncompressed. If a client does not take special care when processing such responses, it may result in excessive CPU and/or memory consumption. An attacker might exploit such a weakness for a DoS attack. To exploit this the attacker must control the location (URL) that superagent makes a request to.

CVSS3: 5.9
nvd
больше 7 лет назад

The HTTP client module superagent is vulnerable to ZIP bomb attacks. In a ZIP bomb attack, the HTTP server replies with a compressed response that becomes several magnitudes larger once uncompressed. If a client does not take special care when processing such responses, it may result in excessive CPU and/or memory consumption. An attacker might exploit such a weakness for a DoS attack. To exploit this the attacker must control the location (URL) that superagent makes a request to.

CVSS3: 5.9
debian
больше 7 лет назад

The HTTP client module superagent is vulnerable to ZIP bomb attacks. I ...

EPSS

Процентиль: 59%
0.00385
Низкий

5.9 Medium

CVSS3

Дефекты

CWE-400
CWE-409