Conversion of property names to strings can trigger infinite recursion
Published Dec 28, 2023
8.6
HIGHCVSS 3.1
EPSS 0.69%
Description
msgpackr is a fast MessagePack NodeJS/JavaScript implementation. Prior to 1.10.1, when decoding user supplied MessagePack messages, users can trigger stuck threads by crafting messages that keep the decoder stuck in a loop. The fix is available in v1.10.1. Exploits seem to require structured cloning, replacing the 0x70 extension with your own (that throws an error or does something other than recursive referencing) should mitigate the issue.
Affected products
-
Affected
- < 1.10.1
No data.
Red Hat Fuse 7
msgpackr
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Fuse 7 | msgpackr | Will not fix | n/a |
msgpackr
npm
Introduced 0 Fixed 1.10.1
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | msgpackr | 0 | 1.10.1 |
Remediation
Red Hat statement
Red Hat rates this as a moderate impact vulnerability since it demands cloning a structure, which leads to high complexity.
Red Hat mitigation
No mitigation is currently found for this CVE.
References (8)
- https://access.redhat.com/security/cve/CVE-2023-52079 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2256134 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-3146 Advisory
- https://github.com/advisories/GHSA-7hpj-7hhx-2fgx Advisory
- https://github.com/kriszyp/msgpackr/commit/18f44f8800e2261341cdf489d1ba1e35a0133602 x_refsource_MISCPatch
- https://github.com/kriszyp/msgpackr/security/advisories/GHSA-7hpj-7hhx-2fgx x_refsource_CONFIRMVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2023-52079
- https://www.cve.org/CVERecord?id=CVE-2023-52079
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2023-52079 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2256134 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-3146 | Advisory | |
| https://github.com/advisories/GHSA-7hpj-7hhx-2fgx | Advisory | |
| https://github.com/kriszyp/msgpackr/commit/18f44f8800e2261341cdf489d1ba1e35a0133602 | x_refsource_MISCPatch | |
| https://github.com/kriszyp/msgpackr/security/advisories/GHSA-7hpj-7hhx-2fgx | x_refsource_CONFIRMVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2023-52079 | ||
| https://www.cve.org/CVERecord?id=CVE-2023-52079 |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub