Skip to content

Crash in HeaderParser in dicer #83

@TheKingTermux

Description

@TheKingTermux

Description

This affects all versions of package dicer. A malicious attacker can send a modified form to server, and crash the nodejs service. A complete denial of service can be achived by sending the malicious form in a loop.

Severity

  • Low
  • Moderate
  • High
  • Critical

7.5 / 10

CVSS base metrics

  • Attack vector
    Network

  • Attack complexity
    Low

  • Privileges required
    None

  • User interaction
    None

  • Scope
    Unchanged

  • Confidentiality
    None

  • Integrity
    None

  • Availability
    High

  • CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

  • Weaknesses
    CWE-248

  • CVE ID
    CVE-2022-24434

  • GHSA ID
    GHSA-wm7h-9275-46v2

Information

  • Package
    dicer (npm)
  • Affected versions
    <= 0.3.1
  • Patched version
    None

References

Metadata

Metadata

Assignees

No one assigned

    Labels

    Auto Create IssuesLabel for Auto Created IssuesHighThis label for Security Severity onlySecurityLabel for Security IssuesSolvedLabel for solved issues / Pr

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions