Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xjhf-7833-3pm5

Опубликовано: 28 авг. 2025
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Volto affected by possible DoS by invoking specific URL by anonymous user

Impact

When visiting a specific URL, an anonymous user could cause the NodeJS server part of Volto to quit with an error.

Patches

The problem has been patched and the patch has been backported to Volto major versions down until 16. It is advised to upgrade to the latest patch release of your respective current major version:

Workarounds

Make sure your setup automatically restarts processes that quit with an error. This won't prevent a crash, but it minimises downtime.

Report

The problem was discovered by FHNW, a client of Plone provider kitconcept, who shared it with the Plone Zope Security Team (security@plone.org).

Пакеты

Наименование

@plone/volto

npm
Затронутые версииВерсия исправления

< 16.34.0

16.34.0

Наименование

@plone/volto

npm
Затронутые версииВерсия исправления

>= 17.0.0, < 17.22.1

17.22.1

Наименование

@plone/volto

npm
Затронутые версииВерсия исправления

>= 18.0.0, < 18.24.0

18.24.0

Наименование

@plone/volto

npm
Затронутые версииВерсия исправления

>= 19.0.0-alpha.1, < 19.0.0-alpha.4

19.0.0-alpha.4

EPSS

Процентиль: 27%
0.00098
Низкий

7.5 High

CVSS3

Дефекты

CWE-755

Связанные уязвимости

CVSS3: 7.5
nvd
5 месяцев назад

Volto is a React based frontend for the Plone Content Management System. In versions from 19.0.0-alpha.1 to before 19.0.0-alpha.4, 18.0.0 to before 18.24.0, 17.0.0 to before 17.22.1, and prior to 16.34.0, an anonymous user could cause the NodeJS server part of Volto to quit with an error when visiting a specific URL. The problem has been patched in versions 16.34.0, 17.22.1, 18.24.0, and 19.0.0-alpha.4. To mitigate downtime, have setup automatically restart processes that quit with an error.

EPSS

Процентиль: 27%
0.00098
Низкий

7.5 High

CVSS3

Дефекты

CWE-755