CVE-2023-37899
19.07.2023, 20:15
Feathersjs is a framework for creating web APIs and real-time applications with TypeScript or JavaScript. Feathers socket handler did not catch invalid string conversion errors like `const message = ${{ toString: '' }}` which would cause the NodeJS process to crash when sending an unexpected Socket.io message like `socket.emit('find', { toString: '' })`. A fix has been released in versions 5.0.8 and 4.5.18. Users are advised to upgrade. There is no known workaround for this vulnerability.Enginsight
Vendor | Product | Version |
---|---|---|
feathersjs | feathers | 𝑥 < 4.5.18 |
feathersjs | feathers | 5.0.0 ≤ 𝑥 < 5.0.8 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References