Executive brief
Feathers is a JavaScript backend framework that uses Socket.io for real-time communication with web clients. The socket handler fails to properly catch exceptions when processing malformed messages containing invalid toString properties, allowing an attacker to crash the Node.js process with a specially crafted message. This results in service unavailability and potential data loss from the unexpected shutdown.
Technical details
The vulnerability is a denial-of-service flaw in the Feathers socket handler caused by unhandled exceptions during implicit string conversion. When processing Socket.io messages, the handler performs string interpolation on message objects without catching TypeError exceptions that occur when an object has a toString property set to a non-function value. An unauthenticated attacker on the network can send a crafted message (e.g., socket.emit('find', { toString: '' })) to trigger the exception and crash the Node.js process. Patches are available in versions 4.5.18, 5.0.8, and later for both @feathersjs/socketio and @feathersjs/transport-commons.
Affected products
- Feathers @feathersjs/socketio 4.5.17 and earlier; 5.0.0 through 5.0.7
- Feathers @feathersjs/transport-commons 4.5.17 and earlier; 5.0.0 through 5.0.7
Timeline
- 2023-07-19: disclosed
- 2023-07-19: patched: Patches released in v4.5.18 and v5.0.8