VDB
Sign up
MEDIUM

GHSA-xgp2-cc4r-7vf6

Denial of Service in http-live-simulator

Quick fix

GHSA-xgp2-cc4r-7vf6 — http-live-simulator: upgrade to the fixed version with the command below.

npm install http-live-simulator@1.0.8

Details

Versions of `http-live-simulator` prior to 1.0.8 are vulnerable to Denial of Service. The package fails to catch an exception that causes the Node process to crash, effectively shutting down the server. This allows an attacker to send an HTTP request that crashes the server.

## Recommendation

Upgrade to version 1.0.8 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/http-live-simulator
Introduced in: 0Fixed in: 1.0.8
Fixnpm install http-live-simulator@1.0.8

References