{"id":"GHSA-gpw9-fwm8-7rx7","summary":"DoS vulnerability for apps with sockets enabled","details":"### Impact\nIn Sails apps \u003c=v1.5.6, an attacker can send a virtual request that will cause the node process to crash. \n\n### Patches\nThis behavior was fixed in Sails [v1.5.7](https://github.com/balderdashy/sails/releases/tag/v1.5.7)\n\n### Workarounds\nDisable the sockets hook and remove the `sails.io.js` client\n\n### References\nhttps://github.com/balderdashy/sails/pull/7287\n\nBig thanks to @ThomasRinsma at [Codean](https://www.linkedin.com/company/codeanio/)!","aliases":["CVE-2023-38504"],"modified":"2023-11-08T04:13:08.434892Z","published":"2023-07-27T17:13:14Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2023-07-27T17:13:14Z","nvd_published_at":"2023-07-27T19:15:10Z","cwe_ids":["CWE-248"],"severity":"HIGH"},"references":[{"type":"WEB","url":"https://github.com/balderdashy/sails/security/advisories/GHSA-gpw9-fwm8-7rx7"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-38504"},{"type":"WEB","url":"https://github.com/balderdashy/sails/pull/7287"},{"type":"WEB","url":"https://github.com/balderdashy/sails/commit/4a023dc5095a4b30fdc8535f705ed34cd22d2f7d"},{"type":"PACKAGE","url":"https://github.com/balderdashy/sails"},{"type":"WEB","url":"https://github.com/balderdashy/sails/releases/tag/v1.5.7"}],"affected":[{"package":{"name":"sails","ecosystem":"npm","purl":"pkg:npm/sails"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.5.7"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/07/GHSA-gpw9-fwm8-7rx7/GHSA-gpw9-fwm8-7rx7.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}