Lucene search

K
githubGitHub Advisory DatabaseGHSA-HPP2-2CR5-PF6G
HistoryFeb 14, 2023 - 9:49 p.m.

Denial of service due to unlimited number of parts

2023-02-1421:49:55
CWE-400
CWE-770
GitHub Advisory Database
github.com
8
denial of service
multipart body parser
file parts
field parts
empty parts
fastify
vulnerability
patch
hackerone.

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

0.001 Low

EPSS

Percentile

50.1%

Impact

  • The multipart body parser accepts an unlimited number of file parts.
  • The multipart body parser accepts an unlimited number of field parts.
  • The multipart body parser accepts an unlimited number of empty parts as field
    parts.

Patches

This is fixed in v7.4.1 (for Fastify v4.x) and v6.0.1 (for Fastify v3.x).

Workarounds

There are no known workaround.

References

Reported at https://hackerone.com/reports/1816195.

Affected configurations

Vulners
Node
fastifyfastify-multipartRange<7.4.1
OR
fastifyfastify-multipartRange<6.0.1

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

0.001 Low

EPSS

Percentile

50.1%

Related for GHSA-HPP2-2CR5-PF6G