Описание
Resource exhaustion in socket.io-parser
The socket.io-parser npm package before versions 3.3.2 and 3.4.1 allows attackers to cause a denial of service (memory consumption) via a large packet because a concatenation approach is used.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2020-36049
- https://github.com/socketio/socket.io-parser/commit/dcb942d24db97162ad16a67c2a0cf30875342d55
- https://blog.caller.xyz/socketio-engineio-dos
- https://github.com/bcaller/kill-engine-io
- https://github.com/socketio/socket.io-parser/releases/tag/3.3.2
- https://github.com/socketio/socket.io-parser/releases/tag/3.4.1
- https://www.npmjs.com/package/socket.io-parser
Пакеты
socket.io-parser
< 3.3.2
3.3.2
socket.io-parser
= 3.4.0
3.4.1
Связанные уязвимости
socket.io-parser before 3.4.1 allows attackers to cause a denial of service (memory consumption) via a large packet because a concatenation approach is used.
socket.io-parser before 3.4.1 allows attackers to cause a denial of service (memory consumption) via a large packet because a concatenation approach is used.
socket.io-parser before 3.4.1 allows attackers to cause a denial of service (memory consumption) via a large packet because a concatenation approach is used.
socket.io-parser before 3.4.1 allows attackers to cause a denial of se ...