Denial-of-service in NodeBB <= v2.8.10 allows...
High severity
Unreviewed
Published
Sep 29, 2023
to the GitHub Advisory Database
•
Updated Apr 4, 2024
Description
Published by the National Vulnerability Database
Sep 29, 2023
Published to the GitHub Advisory Database
Sep 29, 2023
Last updated
Apr 4, 2024
Denial-of-service in NodeBB <= v2.8.10 allows unauthenticated attackers to trigger a crash, when invoking
eventName.startsWith()
oreventName.toString()
, while processing Socket.IO messages via crafted Socket.IO messages containing array or object type for the event name respectively.References