Описание
Fastify node module before 0.38.0 is vulnerable to a denial-of-service attack by sending a request with "Content-Type: application/json" and a very large payload.
Ссылки
- ExploitIssue TrackingThird Party Advisory
- ExploitIssue TrackingThird Party Advisory
- ExploitIssue TrackingThird Party Advisory
- ExploitIssue TrackingThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 0.38.0 (исключая)
cpe:2.3:a:fastify:fastify:*:*:*:*:*:node.js:*:*
EPSS
Процентиль: 73%
0.00776
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-770
CWE-770
Связанные уязвимости
CVSS3: 7.5
github
больше 7 лет назад
Denial of Service vulnerability with large JSON payloads in fastify
EPSS
Процентиль: 73%
0.00776
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-770
CWE-770