CVE-2023-38504

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
27/07/2023
Last modified:
03/08/2023

Description

Sails is a realtime MVC Framework for Node.js. In Sails apps prior to version 1.5.7,, an attacker can send a virtual request that will cause the node process to crash. This behavior was fixed in Sails v1.5.7. As a workaround, disable the sockets hook and remove the `sails.io.js` client.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:sailsjs:sails:*:*:*:*:*:node.js:*:* 1.5.7 (excluding)