Junglewise Threat Intelligence

CVE-2021-41167: modern-async uncontrolled resource consumption in forEachSeries and forEachLimit

CVE-2021-41167 · Severity: low · CVSS 3.1 · Published 2021-10-21

Vendors: npm.

Executive brief

A bug in the modern-async JavaScript library prevents it from properly limiting the number of simultaneous tasks it performs. This library is used by developers to manage complex background operations in web applications. If an application uses this library to process user requests, an attacker could trigger a large number of tasks at once, potentially overwhelming the server and causing a service outage.

Technical details

A vulnerability exists in the modern-async library where the `forEachSeries` and `forEachLimit` functions fail to properly await the iteratee function. This root cause is a missing `await` keyword in the internal implementation, which causes all asynchronous tasks to be triggered simultaneously regardless of the specified concurrency limit. An attacker can exploit this by providing a large input set to an application endpoint that utilizes these functions, leading to uncontrolled resource consumption (CWE-770) and potential Denial of Service (DoS). The issue is fixed in version 1.0.4 by correctly awaiting the iteratee calls.

Affected products

  • nicolas-van modern-async < 1.0.4

Timeline

  • 2021-10-20: disclosed: Issue reported on GitHub
  • 2021-10-20: patched: Fix committed to repository
  • 2021-10-21: advisory

References