mirror of
https://github.com/0xMarcio/cve.git
synced 2025-05-06 02:31:38 +00:00
850 B
850 B
CVE-2023-30591
Description
Denial-of-service in NodeBB <= v2.8.10 allows unauthenticated attackers to trigger a crash, when invoking eventName.startsWith()
or eventName.toString()
, while processing Socket.IO messages via crafted Socket.IO messages containing array or object type for the event name respectively.