Ws Project Ws 7.2.3 for Node.js

CPE Details

Ws Project Ws 7.2.3 for Node.js
7.2.3
2021-05-28
14h44 +00:00
2021-06-01
16h39 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:ws_project:ws:7.2.3:*:*:*:*:node.js:*:*

Informations

Vendor

ws_project

Product

ws

Version

7.2.3

Target Software

node.js

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2021-32640 2021-05-25 16h25 +00:00 ws is an open source WebSocket client and server library for Node.js. A specially crafted value of the `Sec-Websocket-Protocol` header can be used to significantly slow down a ws server. The vulnerability has been fixed in ws@7.4.6 (https://github.com/websockets/ws/commit/00c425ec77993773d823f018f64a5c44e17023ff). In vulnerable versions of ws, the issue can be mitigated by reducing the maximum allowed length of the request headers using the [`--max-http-header-size=size`](https://nodejs.org/api/cli.html#cli_max_http_header_size_size) and/or the [`maxHeaderSize`](https://nodejs.org/api/http.html#http_http_createserver_options_requestlistener) options.
5.3
Medium