{"id":"GHSA-3hjg-vc7r-rcrw","summary":"Denial of Service vulnerability in @podium/layout and @podium/proxy","details":"### Impact\nAn attacker using the `Trailer` header as part of the request against proxy endpoints has the ability to take down the server.\nAll Podium layouts that include podlets with proxy endpoints are affected.\n\n### Patches\n`@podium/layout` which is the main way developers/users are vulnerable to this exploit, has been patched in version `4.6.110`. All earlier versions are vulnerable.\n`@podium/proxy` which is the source of the vulnerability and is used by `@podium/layout` has been patched in version `4.2.74`. All earlier versions are vulnerable.\n\n### Workarounds\nIt is not easily possible to work around this issue without upgrading. We recommend upgrading `@podium/layout` and/or `@podium/proxy` as soon as possible.\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Open an issue in [podium-lib/issues](https://github.com/podium-lib/issues)\n\n### Credits\nThe vulnerability was reported by [krynos](https://hackerone.com/krynos) from [Ercoli Consulting](https://www.ercoliconsulting.eu/) via FINN.no's private bug bounty program\n","aliases":["CVE-2022-24822"],"modified":"2023-11-08T04:08:37.756263Z","published":"2022-04-07T15:20:23Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2022-04-07T15:20:23Z","nvd_published_at":"2022-04-06T18:15:00Z","cwe_ids":["CWE-248"],"severity":"HIGH"},"references":[{"type":"WEB","url":"https://github.com/podium-lib/proxy/security/advisories/GHSA-3hjg-vc7r-rcrw"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-24822"},{"type":"WEB","url":"https://github.com/podium-lib/layout/commit/fe43e655432b0a5f07b6475f67babcc2588fb039"},{"type":"WEB","url":"https://github.com/podium-lib/proxy/commit/9698a40df081217ce142d4de71f929baaa339cdf"},{"type":"WEB","url":"https://github.com/podium-lib/layout/releases/tag/v4.6.110"},{"type":"WEB","url":"https://github.com/podium-lib/proxy/releases/tag/v4.2.74"}],"affected":[{"package":{"name":"@podium/layout","ecosystem":"npm","purl":"pkg:npm/%40podium/layout"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"4.6.110"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/04/GHSA-3hjg-vc7r-rcrw/GHSA-3hjg-vc7r-rcrw.json"}},{"package":{"name":"@podium/proxy","ecosystem":"npm","purl":"pkg:npm/%40podium/proxy"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"4.2.74"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/04/GHSA-3hjg-vc7r-rcrw/GHSA-3hjg-vc7r-rcrw.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}