QID 983872
QID 983872: Nodejs (npm) Security Update for nes (GHSA-3pwh-5mmc-mwrx)
Affected versions of `nes` are vulnerable to denial of service when given an invalid `cookie` header, and websocket authentication is set to `cookie`. Submitting an invalid cookie on the websocket upgrade request will cause the node process to throw and exit. ## Recommendation Update to version 6.4.1 or later.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-3pwh-5mmc-mwrx for updates pertaining to this vulnerability.
Vendor References
- GHSA-3pwh-5mmc-mwrx -
github.com/advisories/GHSA-3pwh-5mmc-mwrx
CVEs related to QID 983872
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-3pwh-5mmc-mwrx | nes |
|