CVE-2022-24434: Crash in HeaderParser in dicer
(updated )
This affects all versions of package dicer. A malicious attacker can send a modified form to server, and crash the nodejs service. An attacker could sent the payload again and again so that the service continuously crashes.
References
- github.com/advisories/GHSA-wm7h-9275-46v2
- github.com/mscdex/busboy/issues/250
- github.com/mscdex/dicer/pull/22
- github.com/mscdex/dicer/pull/22/commits/b7fca2e93e8e9d4439d8acc5c02f5e54a0112dac
- nvd.nist.gov/vuln/detail/CVE-2022-24434
- snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-2838865
- snyk.io/vuln/SNYK-JS-DICER-2311764
Detect and mitigate CVE-2022-24434 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →