Vulnerability CVE-2022-24434


Published: 2022-05-20

Description:
This affects all versions of package dicer. A malicious attacker can send a modified form to server, and crash the nodejs service. An attacker could sent the payload again and again so that the service continuously crashes.

 References:
https://snyk.io/vuln/SNYK-JS-DICER-2311764
https://github.com/mscdex/dicer/pull/22/commits/b7fca2e93e8e9d4439d8acc5c02f5e54a0112dac
https://github.com/mscdex/dicer/pull/22
https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-2838865
https://github.com/mscdex/busboy/issues/250

Copyright 2026, cxsecurity.com

 

Back to Top