7.5

CVE-2022-25940

Exploit

Denial of Service (DoS)

All versions of package lite-server are vulnerable to Denial of Service (DoS) when an attacker sends an HTTP request and includes control characters that the decodeURI() function is unable to parse.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Lite-server ProjectLite-server Version- SwPlatformnode.js
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.16% 0.629
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
report@snyk.io 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

https://gist.github.com/lirantal/832382155e00da92bfd8bb3adea474eb
Third Party Advisory
Exploit
https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-3175617
Third Party Advisory
Exploit
https://security.snyk.io/vuln/SNYK-JS-LITESERVER-3153540
Third Party Advisory
Exploit