Executive brief
Sails is a popular Node.js web framework for building real-time applications. Versions up to 1.5.6 contain a denial of service vulnerability in the sockets module that allows an attacker to send a specially crafted virtual request, causing the entire Node.js process to crash and disrupting service availability for all users.
Technical details
The vulnerability is an uncaught exception (CWE-248) in the Sails sockets module that fails to properly handle certain virtual requests. An attacker on the network can send a malicious virtual request to an app with sockets enabled, triggering an unhandled exception that crashes the Node.js process. The attack requires no authentication, no special privileges, and the app must have the sockets hook enabled (which is default). The vulnerability was fixed in Sails v1.5.7 by properly catching and handling the exception. Workarounds include disabling the sockets hook and removing the sails.io.js client.
Affected products
- Balderdashy Sails <=1.5.6
Timeline
- 2023-07-27: disclosed
- 2023-07-27: patched: Fixed in Sails v1.5.7