Описание
All versions of package lite-server are vulnerable to Denial of Service (DoS) when an attacker sends an HTTP request and includes control characters that the decodeURI() function is unable to parse.
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
- ExploitThird Party Advisory
- ExploitThird Party Advisory
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:lite-server_project:lite-server:-:*:*:*:*:node.js:*:*
EPSS
Процентиль: 66%
0.00508
Низкий
7.5 High
CVSS3
Дефекты
NVD-CWE-Other
CWE-20
Связанные уязвимости
EPSS
Процентиль: 66%
0.00508
Низкий
7.5 High
CVSS3
Дефекты
NVD-CWE-Other
CWE-20