Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-49800

Опубликовано: 09 дек. 2023
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

nuxt-api-party is an open source module to proxy API requests. The library allows the user to send many options directly to ofetch. There is no filter on which options are available. We can abuse the retry logic to cause the server to crash from a stack overflow. fetchOptions are obtained directly from the request body. A malicious user can construct a URL known to not fetch successfully, then set the retry attempts to a high value, this will cause a stack overflow as ofetch error handling works recursively resulting in a denial of service. This issue has been addressed in version 0.22.1. Users are advised to upgrade. Users unable to upgrade should limit ofetch options.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:johannschopplich:nuxt_api_party:*:*:*:*:*:node.js:*:*
Версия до 0.21.3 (включая)

EPSS

Процентиль: 78%
0.01121
Низкий

7.5 High

CVSS3

Дефекты

CWE-400
CWE-787

Связанные уязвимости

CVSS3: 7.5
github
около 2 лет назад

DOS by abusing `fetchOptions.retry`.

EPSS

Процентиль: 78%
0.01121
Низкий

7.5 High

CVSS3

Дефекты

CWE-400
CWE-787