CVE-2020-8192: Medium severity fastify fastify node.js vulnerability
Published Jul 30, 2020
·Updated
A denial of service vulnerability exists in Fastify v2.14.1 and v3.0.0-rc.4 that allows a malicious user to trigger resource exhaustion (when the allErrors option is used) with specially crafted schemas.
Affected Software
2 affected components
fastify Fastify Node.js=2.14.1
fastify Fastify Node.js=3.0.0-rc4
Event History
Jul 30, 2020
CVE Published
via MITRE·12:53 PM
Data Sourced
via MITRE·12:53 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-8192?
CVE-2020-8192 is classified as a denial of service vulnerability.
2
How do I fix CVE-2020-8192?
To mitigate CVE-2020-8192, avoid using the allErrors option with untrusted schemas in Fastify versions 2.14.1 and 3.0.0-rc.4.
3
Which versions of Fastify are affected by CVE-2020-8192?
CVE-2020-8192 affects Fastify version 2.14.1 and version 3.0.0-rc.4.
4
What does CVE-2020-8192 exploit?
CVE-2020-8192 exploits resource exhaustion through specially crafted schemas when the allErrors option is enabled.
5
Can I upgrade Fastify to fix CVE-2020-8192?
Upgrading Fastify to a version after 2.14.1 or 3.0.0-rc.4 will resolve the vulnerability in CVE-2020-8192.