This affects all versions of package dicer. A malicious attacker can send a modified form to server, and crash the nodejs service. A complete denial of service can be achived by sending the malicious form in a loop.
References
- https://nvd.nist.gov/vuln/detail/CVE-2022-24434
- https://github.com/mscdex/busboy/issues/250
- https://github.com/mscdex/dicer/pull/22
- https://github.com/mscdex/dicer/pull/22/commits/b7fca2e93e8e9d4439d8acc5c02f5e54a0112dac
- https://snyk.io/vuln/SNYK-JS-DICER-2311764
- https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-2838865
- https://github.com/advisories/GHSA-wm7h-9275-46v2