GHSA-r7qp-cfhv-p84w

Suggest an improvement
Source
https://github.com/advisories/GHSA-r7qp-cfhv-p84w
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/11/GHSA-r7qp-cfhv-p84w/GHSA-r7qp-cfhv-p84w.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-r7qp-cfhv-p84w
Aliases
Published
2022-11-21T23:55:41Z
Modified
2023-11-08T04:10:36Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Uncaught exception in engine.io
Details

Impact

A specially crafted HTTP request can trigger an uncaught exception on the Engine.IO server, thus killing the Node.js process.

events.js:292
      throw er; // Unhandled 'error' event
      ^

Error: read ECONNRESET
    at TCP.onStreamRead (internal/stream_base_commons.js:209:20)
Emitted 'error' event on Socket instance at:
    at emitErrorNT (internal/streams/destroy.js:106:8)
    at emitErrorCloseNT (internal/streams/destroy.js:74:3)
    at processTicksAndRejections (internal/process/task_queues.js:80:21) {
  errno: -104,
  code: 'ECONNRESET',
  syscall: 'read'
}

This impacts all the users of the engine.io package, including those who uses depending packages like socket.io.

Patches

A fix has been released today (2022/11/20):

Version range Fixed version
engine.io@3.x.y 3.6.1
engine.io@6.x.y 6.2.1

For socket.io users:

Version range engine.io version Needs minor update?
socket.io@4.5.x ~6.2.0 npm audit fix should be sufficient
socket.io@4.4.x ~6.1.0 Please upgrade to socket.io@4.5.x
socket.io@4.3.x ~6.0.0 Please upgrade to socket.io@4.5.x
socket.io@4.2.x ~5.2.0 Please upgrade to socket.io@4.5.x
socket.io@4.1.x ~5.1.1 Please upgrade to socket.io@4.5.x
socket.io@4.0.x ~5.0.0 Please upgrade to socket.io@4.5.x
socket.io@3.1.x ~4.1.0 Please upgrade to socket.io@4.5.x (see here)
socket.io@3.0.x ~4.0.0 Please upgrade to socket.io@4.5.x (see here)
socket.io@2.5.0 ~3.6.0 npm audit fix should be sufficient
socket.io@2.4.x and below ~3.5.0 Please upgrade to socket.io@2.5.0

Workarounds

There is no known workaround except upgrading to a safe version.

For more information

If you have any questions or comments about this advisory:

Thanks to Jonathan Neve for the responsible disclosure.

Database specific
{
    "cwe_ids":  [
        "CWE-248"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2022-11-21T23:55:41Z",
    "nvd_published_at":  "2022-11-22T01:15:00Z",
    "severity":  "MODERATE"
}
References

Affected packages

npm / engine.io

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.6.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/11/GHSA-r7qp-cfhv-p84w/GHSA-r7qp-cfhv-p84w.json"

npm / engine.io

Package

Affected ranges

Type
SEMVER
Events
Introduced
4.0.0
Fixed
6.2.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/11/GHSA-r7qp-cfhv-p84w/GHSA-r7qp-cfhv-p84w.json"