{"id":"GHSA-86ch-6w7v-v6xf","summary":"Denial of Service in soketi","details":"### Impact\n_What kind of vulnerability is it? Who is impacted?_\n\nThere was a wrong behavior when reading POST requests, making the server crash if it couldn't read the body. In case a POST request was sent to any endpoint of the server with an empty body, **even unauthenticated with the Pusher Protocol**, it would simply just crash the server for trying to send a response after the request closed.\n\nAll users that run the server are affected by it and it's highly recommended to upgrade to the latest patch.\n\n### Patches\n_Has the problem been patched? What versions should users upgrade to?_\n\nUpdating to at least 0.24.1 or the latest version.\n\n### Workarounds\n_Is there a way for users to fix or remediate the vulnerability without upgrading?_\n\nNo. Upgrading is the only solution.\n\n### References\n_Are there any links users can visit to find out more?_\n\nhttps://github.com/soketi/soketi/releases/tag/0.24.1\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Open an issue in [the issues board](https://github.com/soketi/soketi/issues)\n* Email us at [alex@renoki.org](mailto:alex@renoki.org)\n","aliases":["CVE-2022-21667"],"modified":"2023-11-08T04:08:06.935571Z","published":"2022-01-08T00:24:44Z","database_specific":{"github_reviewed_at":"2022-01-07T23:46:31Z","nvd_published_at":"2022-01-10T14:12:00Z","cwe_ids":["CWE-755"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/soketi/soketi/security/advisories/GHSA-86ch-6w7v-v6xf"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-21667"},{"type":"WEB","url":"https://github.com/soketi/soketi/commit/4b12efef9c31117c36a0a0f1c3aa32114e86364b"},{"type":"PACKAGE","url":"https://github.com/soketi/soketi"},{"type":"WEB","url":"https://github.com/soketi/soketi/releases/tag/0.24.1"}],"affected":[{"package":{"name":"@soketi/soketi","ecosystem":"npm","purl":"pkg:npm/%40soketi/soketi"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.24.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/01/GHSA-86ch-6w7v-v6xf/GHSA-86ch-6w7v-v6xf.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}