You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
DoS vulnerability for apps with sockets enabled
High severity
GitHub Reviewed
Published
Jul 27, 2023
in
balderdashy/sails
•
Updated Nov 6, 2023
Impact
In Sails apps <=v1.5.6, an attacker can send a virtual request that will cause the node process to crash.
Patches
This behavior was fixed in Sails v1.5.7
Workarounds
Disable the sockets hook and remove the
sails.io.js
clientReferences
balderdashy/sails#7287
Big thanks to @ThomasRinsma at Codean!
References