Логотип exploitDog
bind:CVE-2023-49800
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-49800

Количество 2

Количество 2

nvd логотип

CVE-2023-49800

около 2 лет назад

`nuxt-api-party` is an open source module to proxy API requests. The library allows the user to send many options directly to `ofetch`. There is no filter on which options are available. We can abuse the retry logic to cause the server to crash from a stack overflow. fetchOptions are obtained directly from the request body. A malicious user can construct a URL known to not fetch successfully, then set the retry attempts to a high value, this will cause a stack overflow as ofetch error handling works recursively resulting in a denial of service. This issue has been addressed in version 0.22.1. Users are advised to upgrade. Users unable to upgrade should limit ofetch options.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-q6hx-3m4p-749h

около 2 лет назад

DOS by abusing `fetchOptions.retry`.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-49800

`nuxt-api-party` is an open source module to proxy API requests. The library allows the user to send many options directly to `ofetch`. There is no filter on which options are available. We can abuse the retry logic to cause the server to crash from a stack overflow. fetchOptions are obtained directly from the request body. A malicious user can construct a URL known to not fetch successfully, then set the retry attempts to a high value, this will cause a stack overflow as ofetch error handling works recursively resulting in a denial of service. This issue has been addressed in version 0.22.1. Users are advised to upgrade. Users unable to upgrade should limit ofetch options.

CVSS3: 7.5
1%
Низкий
около 2 лет назад
github логотип
GHSA-q6hx-3m4p-749h

DOS by abusing `fetchOptions.retry`.

CVSS3: 7.5
1%
Низкий
около 2 лет назад

Уязвимостей на страницу