This affects all versions of package dicer. A malicious attacker can send a modified form to server, and crash the nodejs service. An attacker could sent the payload again and again so that the service continuously crashes.
Link | Tags |
---|---|
https://snyk.io/vuln/SNYK-JS-DICER-2311764 | third party advisory exploit |
https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-2838865 | third party advisory exploit |
https://github.com/mscdex/dicer/pull/22 | issue tracking patch exploit third party advisory |
https://github.com/mscdex/busboy/issues/250 | third party advisory patch |
https://github.com/mscdex/dicer/pull/22/commits/b7fca2e93e8e9d4439d8acc5c02f5e54a0112dac | third party advisory patch |