Launch Week Day 1: Announcing Security Design Review
MEDIUM 6.5 npm

NocoDB vulnerable to Denial of Service

GHSA-grv6-m753-3w2g · CVE-2022-3423

Published · Modified

Description

NocoDB prior to 0.92.0 allows actors to insert large characters into the input field New Project on the create field, which can cause a Denial of Service (DoS) via a crafted HTTP request. Version 0.92.0 fixes this issue.

Ready to move

Start Securing

Free, no credit card | First findings in minutes