CVE-2022-25940

Description

All versions of package lite-server are vulnerable to Denial of Service (DoS) when an attacker sends an HTTP request and includes control characters that the decodeURI() function is unable to parse.

Risk Information

Base Score
7.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
0.508

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2022-25940 are affected in Webjars - lite-server 2.2.0Windows
Vulnerabilities CVE-2022-25940 are affected in Webjars - lite-server for Linux 2.2.0Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234