GHSA-8gpg-466c-5cpj
Dashboard / Vulnerabilities / GHSA-8gpg-466c-5cpj
Summary: Apache SkyWalking NodeJS Agent can lose availability if header includes illegal SkyWalking header
Details: A vulnerability in Apache SkyWalking NodeJS Agent prior to 0.5.1. The vulnerability will cause NodeJS services that has this agent installed to be unavailable if the OAP is unhealthy and NodeJS agent can't establish the connection.
References: https://nvd.nist.gov/vuln/detail/CVE-2022-36127, https://github.com/apache/skywalking-nodejs, https://lists.apache.org/thread/x238wo4r5goy39dxdjcmlofp6gcdnqr3, https://skywalking.apache.org/events/release-apache-skywalking-nodejs-0-5-1, http://www.openwall.com/lists/oss-security/2022/07/18/1
Affected packages
Package
Name: skywalking-backend-js
Purl: pkg:npm/skywalking-backend-js
Affected ranges
Type: SEMVER
Events:
