ws Project ws 6.1.2 for Node.js

CPE Details

ws Project ws 6.1.2 for Node.js
6.1.2
2019-06-18
16h16 +00:00
2019-06-18
16h16 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:ws_project:ws:6.1.2:*:*:*:*:node.js:*:*

Informations

Vendor

ws_project

Product

ws

Version

6.1.2

Target Software

node.js

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2021-32640 2021-05-25 16h25 +00:00 ws is an open source WebSocket client and server library for Node.js. A specially crafted value of the `Sec-Websocket-Protocol` header can be used to significantly slow down a ws server. The vulnerability has been fixed in ws@7.4.6 (https://github.com/websockets/ws/commit/00c425ec77993773d823f018f64a5c44e17023ff). In vulnerable versions of ws, the issue can be mitigated by reducing the maximum allowed length of the request headers using the [`--max-http-header-size=size`](https://nodejs.org/api/cli.html#cli_max_http_header_size_size) and/or the [`maxHeaderSize`](https://nodejs.org/api/http.html#http_http_createserver_options_requestlistener) options.
5.3
Medium