Junglewise Threat Intelligence

CVE-2023-5573: Vrite SDK resource exhaustion via unbounded allocation

CVE-2023-5573 · Severity: low · CVSS 3 · Published 2023-10-13

Technologies: @vrite/sdk (npm). Vendors: npm.

Executive brief

Vrite is an open-source content management and editing platform used to create and manage digital documents. Versions prior to 0.3.0 contain a flaw where an authenticated administrator can trigger unbounded resource allocation on the server without any rate limiting or throttling controls. An attacker with admin credentials could exploit this to exhaust server memory or CPU, causing the application to slow down or become unavailable to legitimate users.

Technical details

The vulnerability is classified as CWE-770 (Allocation of Resources Without Limits or Throttling) in the @vrite/sdk npm package. The root cause involves insufficient resource consumption controls in API endpoints accessible to authenticated users with high privileges (administrator role). An attacker with admin-level access can make requests that allocate unbounded resources without hitting rate limits, throttling mechanisms, or resource caps. This enables denial-of-service conditions by exhausting available server resources. The vulnerability was patched in version 0.3.0, as indicated by commit 1877683 which introduced CORS configuration improvements and other architectural changes. No network-level authentication bypass is required; exploitation requires valid admin credentials.

Affected products

  • Vrite @vrite/sdk before 0.3.0

Timeline

  • 2023-10-13: disclosed: Vulnerability published on GitHub Advisory Database and NVD
  • 2023-10-10: patched: Fix released in version 0.3.0

References

Related threats