Vulnerabilities/

Unauthenticated Denial of Service in the octokit/webhooks library

Severity:
High

Description

Versions v9.26.0, v10.9.x), v11.1.x, v12.0.x all contained the code that would throw the error.

Specifically, during a pentest we encountered a bug in the octokit/webhooks library (a dependency of Probot, a framework for building Github Apps). The resulting request was found to cause an uncaught exception that ends the nodejs process.

Recommendation

Update the octokit package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
octokit
Anything's wrong? Let us know Last updated on December 16, 2023

This issue is available in SmartScanner Professional

See Pricing