Lucene search

K
cveGitHub_MCVE-2022-39386
HistoryNov 08, 2022 - 10:15 p.m.

CVE-2022-39386

2022-11-0822:15:15
CWE-248
GitHub_M
web.nvd.nist.gov
53
@fastify/websocket
cve-2022-39386
security vulnerability
upgrade
nvd
patch

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

38.4%

@fastify/websocket provides WebSocket support for Fastify. Any application using @fastify/websocket could crash if a specific, malformed packet is sent. All versions of fastify-websocket are also impacted. That module is deprecated, so it will not be patched. This has been patched in version 7.1.1 (fastify v4) and version 5.0.1 (fastify v3). There are currently no known workarounds. However, it should be possible to attach the error handler manually. The recommended path is upgrading to the patched versions.

Affected configurations

Nvd
Vulners
Node
fastifywebsocketRange6.0.07.1.1node.js
OR
fastifywebsocketMatch5.0.0node.js
VendorProductVersionCPE
fastifywebsocket*cpe:2.3:a:fastify:websocket:*:*:*:*:*:node.js:*:*
fastifywebsocket5.0.0cpe:2.3:a:fastify:websocket:5.0.0:*:*:*:*:node.js:*:*

CNA Affected

[
  {
    "vendor": "fastify",
    "product": "fastify-websocket",
    "versions": [
      {
        "version": ">= 5.0.0, < 5.0.1",
        "status": "affected"
      },
      {
        "version": ">= 6.0.0, < 7.1.1",
        "status": "affected"
      },
      {
        "version": "<= 4.3.0",
        "status": "affected"
      }
    ]
  }
]

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

38.4%

Related for CVE-2022-39386