QID 981320
QID 981320: Nodejs (npm) Security Update for rendertron (GHSA-4q69-q4q7-x82c)
Rendertron 1.0.0 includes an _ah/stop route to shutdown the Chrome instance responsible for serving render requests to all users. Visiting this route with a GET request allows any unauthorized remote attacker to disable the core service of the application.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-4q69-q4q7-x82c for updates pertaining to this vulnerability.
Vendor References
- GHSA-4q69-q4q7-x82c -
github.com/advisories/GHSA-4q69-q4q7-x82c
CVEs related to QID 981320
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-4q69-q4q7-x82c | rendertron |
|