HIGH7.5
GHSA-xxc2-j7jj-6g5m
Raneto Denial of Service via crafted payload injected into `Search` parameter
Quick fix
GHSA-xxc2-j7jj-6g5m — raneto: upgrade to the fixed version with the command below.
npm install raneto@0.17.1Details
An issue in Renato v0.17.0 allows attackers to cause a Denial of Service (DoS) via a crafted payload injected into the `Search` parameter.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2022-35142[ADVISORY]
- https://github.com/ryanlelek/Raneto/issues/368[WEB]
- https://github.com/ryanlelek/Raneto/pull/370[WEB]
- https://cwe.mitre.org/data/definitions/703.html[WEB]
- https://gainsec.com/2022/08/04/cve-2022-35142-cve-2022-35143-cve-2022-35144[WEB]
- https://github.com/gilbitron/Raneto/releases[WEB]
- https://github.com/ryanlelek/Raneto[PACKAGE]
- https://github.com/ryanlelek/Raneto/releases/tag/0.17.1[WEB]
- http://raneto.com[WEB]