Uncaught Exception Affecting sails package, versions <1.5.7
Threat Intelligence
EPSS
0.11% (45th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-JS-SAILS-5808437
- published 28 Jul 2023
- disclosed 28 Jul 2023
- credit ThomasRinsma
Introduced: 28 Jul 2023
CVE-2023-38504 Open this link in a new tabHow to fix?
Upgrade sails
to version 1.5.7 or higher.
Overview
sails is a framework for building realtime apps, using MVC conventions (based on Express and Socket.io).
Affected versions of this package are vulnerable to Uncaught Exception. An attacker can send a virtual request that will cause the node process to crash.
Workaround
Users who are unable to upgrade to the fixed version can disable the sockets hook and remove the sails.io.js
client.
References
CVSS Scores
version 3.1