ws jest open source klientem i serwerem WebSocket dla Node.js. Przed wersją 8.20.1, implementacja websocket.close() jest podatna na ujawnienie niezainicjowanej pamięci, gdy TypedArray jest przekazywany jako argument reason. Luka została naprawiona w wersji 8.20.1.
▸ Pokaż oryginał (EN)
ws is an open source WebSocket client and server for Node.js. Prior to 8.20.1, the websocket.close() implementation is vulnerable to uninitialized memory disclosure when a TypedArray is passed as the reason argument. This vulnerability is fixed in 8.20.1.
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:NWs Project Ws
APPWs Project8.0.0 – 8.20.1 (bez)
Powiązane podatności
ws is an open source WebSocket client and server for Node.js. All versions from 1.1.0 up to (but not including...
A vulnerability was found in the ping functionality of the ws module before 1.0.0 which allowed clients to all...
ws is a "simple to use, blazing fast and thoroughly tested websocket client, server and console for node.js, u...
ws is an open source WebSocket client and server library for Node.js. A specially crafted value of the `Sec-We...