[13] body-parser vulnerable to denial of service when url encoding is enabled #370

Open
opened 2024-09-23 18:38:06 +01:00 by Helpdesk · 0 comments
Member

Package: body-parser (npm)
Affected versions: < 1.20.3
Patched version: 1.20.3


Impact

body-parser <1.20.3 is vulnerable to denial of service when url encoding is enabled. A malicious actor using a specially crafted payload could flood the server with a large number of requests, resulting in denial of service.

Patches

this issue is patched in 1.20.3

References

Package: body-parser (npm) Affected versions: < 1.20.3 Patched version: 1.20.3 --- ## Impact body-parser <1.20.3 is vulnerable to denial of service when url encoding is enabled. A malicious actor using a specially crafted payload could flood the server with a large number of requests, resulting in denial of service. ## Patches this issue is patched in 1.20.3 ## References
Helpdesk added the
type
alert
label 2024-09-23 18:38:09 +01:00
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference: External/card-drop#370
No description provided.