Rewterz
Rewterz Threat Advisory – CVE-2020-27194 – Linux Kernel scalar32_min_max_or function denial of service
October 19, 2020
Rewterz
Rewterz Threat Alert – Latest AZORult IOCs
October 20, 2020

Rewterz Threat Advisory – Node.js npm-user-validate module denial of service

Severity

Medium

Analysis Summary

Node.js npm-user-validate module is vulnerable to a denial of service, caused by a flaw when processing long input strings begin with @ characters for user emails. By sending a specially-crafted input, a remote attacker could exploit this vulnerability to cause a denial of service condition.

Impact

Denial of service

Affected Vendors

NodeJs

Remediation

Upgrade to the latest version of npm-user-validate (1.0.1 or later).