HIGH7.5
GHSA-gpw9-fwm8-7rx7
DoS vulnerability for apps with sockets enabled
Quick fix
GHSA-gpw9-fwm8-7rx7 — sails: upgrade to the fixed version with the command below.
npm install sails@1.5.7Details
### Impact In Sails apps <=v1.5.6, an attacker can send a virtual request that will cause the node process to crash.
### Patches This behavior was fixed in Sails [v1.5.7](https://github.com/balderdashy/sails/releases/tag/v1.5.7)
### Workarounds Disable the sockets hook and remove the `sails.io.js` client
### References https://github.com/balderdashy/sails/pull/7287
Big thanks to @ThomasRinsma at [Codean](https://www.linkedin.com/company/codeanio/)!
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/balderdashy/sails/security/advisories/GHSA-gpw9-fwm8-7rx7[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2023-38504[ADVISORY]
- https://github.com/balderdashy/sails/pull/7287[WEB]
- https://github.com/balderdashy/sails/commit/4a023dc5095a4b30fdc8535f705ed34cd22d2f7d[WEB]
- https://github.com/balderdashy/sails[PACKAGE]
- https://github.com/balderdashy/sails/releases/tag/v1.5.7[WEB]