Description
Denial-of-service in NodeBB <= v2.8.10 allows unauthenticated attackers to trigger a crash, when invoking `eventName.startsWith()` or `eventName.toString()`, while processing Socket.IO messages via crafted Socket.IO messages containing array or object type for the event name respectively.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-34971 | Denial-of-service in NodeBB <= v2.8.10 allows unauthenticated attackers to trigger a crash, when invoking `eventName.startsWith()` or `eventName.toString()`, while processing Socket.IO messages via crafted Socket.IO messages containing array or object type for the event name respectively. |
References
History
Mon, 23 Sep 2024 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: STAR_Labs
Published:
Updated: 2024-09-23T17:39:24.175Z
Reserved: 2023-04-13T04:12:59.954Z
Link: CVE-2023-30591
Updated: 2024-08-02T14:28:51.967Z
Status : Modified
Published: 2023-09-29T06:15:09.870
Modified: 2024-11-21T08:00:28.840
Link: CVE-2023-30591
No data.
OpenCVE Enrichment
No data.
EUVD