Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:38184
HistoryNov 23, 2022 - 8:32 a.m.

Denial Of Service (DoS)

2022-11-2308:32:44
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
9
dos vulnerability
nodejs crash
http request not triggered

0.001 Low

EPSS

Percentile

35.4%

engine.io is vulnerable to denial of service. The vulnerability exists in setTimeout parameter in server.js because the HTTP request is not properly triggered which allows to attacker to crash NodeJS.

0.001 Low

EPSS

Percentile

35.4%