Junglewise Threat Intelligence

CVE-2022-24434: dicer crash in HeaderParser via malicious multipart data

CVE-2022-24434 · Severity: low · CVSS 3.1 · Published 2022-05-21

Vendors: npm, Maven.

Executive brief

dicer is a Node.js library for parsing multipart form data. A flaw in the HeaderParser allows an attacker to send a specially crafted form to crash the entire Node.js service, achieving a complete denial of service by repeating the attack. This can disrupt applications relying on dicer for handling file uploads and form submissions.

Technical details

The vulnerability is an improper error handling issue (CWE-248) in dicer's HeaderParser component. An attacker can send a modified multipart/form-data request with malicious header names that triggers an unhandled crash in the Node.js process. The attack requires only network access and a simple HTTP request with no authentication; no user interaction is needed. By sending the malicious form repeatedly, an attacker can achieve a sustained denial of service. The fix is available in commit b7fca2e93e8e9d4439d8acc5c02f5e54a0112dac and pull request mscdex/dicer#22.

Affected products

  • mscdex dicer all versions through 0.3.1

Timeline

  • 2022-05-20: disclosed: NVD publication date
  • 2022-05-21: advisory: GHSA-wm7h-9275-46v2 published
  • 2022-05-25: patched: GitHub reviewed fix available (commit b7fca2e93e8e9d4439d8acc5c02f5e54a0112dac)

References