Junglewise Threat Intelligence

CVE-2023-38504: Sails denial of service through virtual socket request

CVE-2023-38504 · Severity: low · CVSS 3.1 · Published 2023-07-27

Technologies: sails (npm). Vendors: npm.

Executive brief

Sails is a popular Node.js web framework for building real-time applications. Versions up to 1.5.6 contain a denial of service vulnerability in the sockets module that allows an attacker to send a specially crafted virtual request, causing the entire Node.js process to crash and disrupting service availability for all users.

Technical details

The vulnerability is an uncaught exception (CWE-248) in the Sails sockets module that fails to properly handle certain virtual requests. An attacker on the network can send a malicious virtual request to an app with sockets enabled, triggering an unhandled exception that crashes the Node.js process. The attack requires no authentication, no special privileges, and the app must have the sockets hook enabled (which is default). The vulnerability was fixed in Sails v1.5.7 by properly catching and handling the exception. Workarounds include disabling the sockets hook and removing the sails.io.js client.

Affected products

  • Balderdashy Sails <=1.5.6

Timeline

  • 2023-07-27: disclosed
  • 2023-07-27: patched: Fixed in Sails v1.5.7

References

Related threats