ZeroHour

CVE-2022-24434

PoC ×3
CVSS 3.1
7.5 high
EPSS
3%p88
Published
()
Modified
Description

This affects all versions of package dicer. A malicious attacker can send a modified form to server, and crash the nodejs service. An attacker could sent the payload again and again so that the service continuously crashes.

Vendors
dicer project
Products
dicer
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.