Описание
ws is a "simple to use, blazing fast and thoroughly tested websocket client, server and console for node.js, up-to-date against RFC-6455". By sending an overly long websocket payload to a ws server, it is possible to crash the node process. This affects ws 1.1.0 and earlier.
Ссылки
- Issue TrackingThird Party Advisory
- Third Party Advisory
- Issue TrackingThird Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.1.0 (включая)
cpe:2.3:a:ws_project:ws:*:*:*:*:*:node.js:*:*
EPSS
Процентиль: 98%
0.66075
Средний
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-400
CWE-20
Связанные уязвимости
CVSS3: 7.5
ubuntu
больше 7 лет назад
ws is a "simple to use, blazing fast and thoroughly tested websocket client, server and console for node.js, up-to-date against RFC-6455". By sending an overly long websocket payload to a `ws` server, it is possible to crash the node process. This affects ws 1.1.0 and earlier.
CVSS3: 7.5
debian
больше 7 лет назад
ws is a "simple to use, blazing fast and thoroughly tested websocket c ...
EPSS
Процентиль: 98%
0.66075
Средний
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-400
CWE-20