Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-50728

Опубликовано: 15 дек. 2023
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

octokit/webhooks is a GitHub webhook events toolset for Node.js. Starting in 9.26.0 and prior to 9.26.3, 10.9.2, 11.1.2, and 12.0.4, there is a problem caused by an issue with error handling in the @octokit/webhooks library because the error can be undefined in some cases. The resulting request was found to cause an uncaught exception that ends the nodejs process. The bug is fixed in octokit/webhooks.js 9.26.3, 10.9.2, 11.1.2, and 12.0.4, app.js 14.02, octokit.js 3.1.2, and Protobot 12.3.3.

An uncaught exception vulnerability was found in octokit webhooks. An error may be undefined in some cases, and the resulting request can cause an uncaught exception that ends the nodejs process.

Отчет

The uncaught exception vulnerability in Octokit webhooks presents a moderate severity issue due to its potential to cause service disruptions and expose applications to unexpected behavior. In technical terms, the absence of proper error handling for undefined errors can lead to unhandled exceptions, ultimately resulting in the termination of the Node.js process. This can impact the availability and reliability of the affected service, affecting its ability to handle incoming requests and potentially leading to downtime.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-755
https://bugzilla.redhat.com/show_bug.cgi?id=2254872octopost/webhooks: uncaught exception

EPSS

Процентиль: 64%
0.00479
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 5.4
nvd
около 2 лет назад

octokit/webhooks is a GitHub webhook events toolset for Node.js. Starting in 9.26.0 and prior to 9.26.3, 10.9.2, 11.1.2, and 12.0.4, there is a problem caused by an issue with error handling in the @octokit/webhooks library because the error can be undefined in some cases. The resulting request was found to cause an uncaught exception that ends the nodejs process. The bug is fixed in octokit/webhooks.js 9.26.3, 10.9.2, 11.1.2, and 12.0.4, app.js 14.02, octokit.js 3.1.2, and Protobot 12.3.3.

CVSS3: 8.2
github
около 2 лет назад

Unauthenticated Denial of Service in the octokit/webhooks library

EPSS

Процентиль: 64%
0.00479
Низкий

7.5 High

CVSS3