Skip to main content

Uncaught Exception

CVE-2023-38504

Severity High
Score 7.5/10

Summary

Sails is a real-time MVC Framework for Node.js. Sails apps in versions prior to 1.5.7, an attacker can send a virtual request that will cause the node process to crash. As a workaround, disable the sockets hook and remove the "sails.io.js" client.

  • LOW
  • NETWORK
  • NONE
  • UNCHANGED
  • NONE
  • NONE
  • NONE
  • HIGH

CWE-248 - Uncaught Exception

An exception is thrown from a function, but it is not caught.

Advisory Timeline

  • Published