GHSA-xgp2-cc4r-7vf6

Suggest an improvement
Source
https://github.com/advisories/GHSA-xgp2-cc4r-7vf6
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-xgp2-cc4r-7vf6/GHSA-xgp2-cc4r-7vf6.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-xgp2-cc4r-7vf6
Published
2020-09-03T20:44:21Z
Modified
2020-08-31T18:50:28Z
Summary
Denial of Service in http-live-simulator
Details

Versions of http-live-simulator prior to 1.0.8 are vulnerable to Denial of Service. The package fails to catch an exception that causes the Node process to crash, effectively shutting down the server. This allows an attacker to send an HTTP request that crashes the server.

Recommendation

Upgrade to version 1.0.8 or later.

Database specific
{
    "cwe_ids":  [],
    "github_reviewed":  true,
    "github_reviewed_at":  "2020-08-31T18:50:28Z",
    "nvd_published_at":  null,
    "severity":  "MODERATE"
}
References

Affected packages

npm / http-live-simulator

Package

Name
http-live-simulator
View open source insights on deps.dev
Purl
pkg:npm/http-live-simulator

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.0.8

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-xgp2-cc4r-7vf6/GHSA-xgp2-cc4r-7vf6.json"