Lucene search

K
githubGitHub Advisory DatabaseGHSA-JPGG-CP2X-QRW3
HistoryDec 28, 2022 - 12:30 a.m.

ecnepsnai/web vulnerable to Uncontrolled Resource Consumption

2022-12-2800:30:23
CWE-400
CWE-476
GitHub Advisory Database
github.com
8
web sockets
authenticatemethod
nil pointer
userdata
authentication bypass
request handlers

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.002

Percentile

57.3%

Web Sockets do not execute any AuthenticateMethod methods which may be set, leading to a nil pointer dereference if the returned UserData pointer is assumed to be non-nil, or authentication bypass. This issue only affects WebSockets with an AuthenticateMethod hook. Request handlers that do not explicitly use WebSockets are not vulnerable.

Affected configurations

Vulners
Node
ecnepsnaiwebRange1.4.01.5.2
VendorProductVersionCPE
ecnepsnaiweb*cpe:2.3:a:ecnepsnai:web:*:*:*:*:*:*:*:*

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.002

Percentile

57.3%

Related for GHSA-JPGG-CP2X-QRW3