Denial of Service in mem
Moderate severity
GitHub Reviewed
Published
Jul 5, 2019
to the GitHub Advisory Database
•
Updated Jan 9, 2023
Description
Reviewed
Jul 3, 2019
Published to the GitHub Advisory Database
Jul 5, 2019
Last updated
Jan 9, 2023
Versions of
mem
prior to 4.0.0 are vulnerable to Denial of Service (DoS). The package fails to remove old values from the cache even after a value passes itsmaxAge
property. This may allow attackers to exhaust the system's memory if they are able to abuse the application logging.Recommendation
Upgrade to version 4.0.0 or later.
References