PT-2023-26484 · Node.Js · Sails

·

CVE-2023-38504

·

Published

2023-07-27

·

Updated

2023-08-03

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Sails versions prior to 1.5.7
Description Sails is a realtime MVC Framework for Node.js. An attacker can send a virtual request that will cause the node process to crash.
Recommendations For versions prior to 1.5.7, update to version 1.5.7 to resolve the issue. As a temporary workaround, consider disabling the sockets hook and removing the sails.io.js client until the update is applied.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-38504
GHSA-GPW9-FWM8-7RX7

Affected Products

Sails