GHSA-7xfp-9c55-5vqj
Remote Memory Exposure in request
Quick fix
GHSA-7xfp-9c55-5vqj — request: upgrade to the fixed version with the command below.
npm install request@2.68.0Details
Affected versions of `request` will disclose local system memory to remote systems in certain circumstances. When a multipart request is made, and the type of `body` is `number`, then a buffer of that size will be allocated and sent to the remote server as the body.
## Proof of Concept
```js var request = require('request'); var http = require('http');
var serveFunction = function (req, res){ req.on('data', function (data) { console.log(data) }); res.end(); }; var server = http.createServer(serveFunction); server.listen(8000);
request({ method: "POST", uri: 'http://localhost:8000', multipart: [{body:500}] },function(err,res,body){}); ```
## Recommendation
Update to version 2.68.0 or later
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2017-16026[ADVISORY]
- https://github.com/request/request/issues/1904[WEB]
- https://github.com/request/request/pull/2018[WEB]
- https://github.com/request/request/pull/2022[WEB]
- https://github.com/request/request/commit/29d81814bc16bc79cb112b4face8be6fc00061dd[WEB]
- https://github.com/request/request[PACKAGE]