davisbarillas / juiceshop

MIT License
0 stars 0 forks source link

Denial of Service: Uncontrolled Resource Consumption in OSS Express Body Parser in `server.ts.anonymous2` #2

Open armorcodegithubapp[bot] opened 4 months ago

armorcodegithubapp[bot] commented 4 months ago

Category : Denial of Service Name : oss-express-body-parser File Locations : server.ts:245 Source Method :server.ts::program:anonymous2 Sink Method : server.ts::program:anonymous2 Finding Link: [https://app.shiftleft.io/findingDetail/Juiceshop/157 ] POST Request to Express Body Parser 'bodyParser()' can create Temporary files and consume space.

Additional information

CWE-400 OWASP-a6

File Path: server.ts:245

Finding Id : 144180553

Tool Finding Id: oss-express-body-parser/933bc33334539b1e26879fcba15deefb

armorcodegithubapp[bot] commented 4 months ago

Finding [144180553] status changed to Confirm Note:
by dbarillas@armorcode.io via ArmorCode Platform