Cross-origin unauthenticated WebSocket DoS: no Origin check + unhandled JSON.parse crashes the server
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 4/5
- Tempo stimato
- 3-5 giorni
- Idoneità per principianti
- 48/100
- Tipo di issue
- Bug
- Chiarezza
- Abbastanza chiara
- Stato di attività
- Attiva
- Stack tecnologico
- javascript
Direzione di ricerca
Inizia in server.js, in setupReloadNotifier intorno alle righe 1002-1003, quindi esamina il gestore delle connessioni updateServer e la gestione del suo handshake WebSocket. Riproduci il caso di frame malformato riportato nell’issue e traccia l’header Origin accettato. Il lavoro è completato quando le origini non attendibili vengono gestite secondo la policy delle origini locali del progetto e i messaggi malformati non terminano più il server.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Summary
The live-reload WebSocket server accepts connections from any origin (no Origin header validation during the handshake), and its message handler calls JSON.parse() on incoming frames with no try/catch. Any web page — including a malicious third-party site a developer merely has open in another browser tab while running eleventy --serve — can open a cross-origin WebSocket to the dev server and send one non-JSON frame to crash the entire process.
CWE: CWE-346 (Origin Validation Error) + CWE-248 (Uncaught Exception)
Severity: High
CVSS: 8.1 — CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:H
Root Cause
server.js (setupReloadNotifier's WebSocket connection handler), around line 1002-1003:
ws.on("message", (data) => {
let parsed = JSON.parse(data.toString()); // no try/catch
...
updateServer.on("connection", ...) never inspects the handshake Origin header before accepting the WebSocket connection, so the classic "malicious webpage attacks your localhost dev server" pattern (the same class of bug behind several historical webpack-dev-server DNS-rebinding/cross-origin advisories) applies here directly.
Reproduction
With the dev server running (see companion issue #150 for setup), from a separate script simulating a cross-origin page:
const ws = new WebSocket("ws://localhost:PORT", { headers: { Origin: "http://evil.example.com" } });
ws.on("open", () => ws.send("NOT-VALID-JSON{{{"));
Server log:
SyntaxError: Unexpected token 'N', "NOT-VALID-JSON{{{" is not valid JSON
at server.js:1003:27
Node.js v22.23.2 [process exits]
Verified: the connection was accepted despite the spoofed Origin header, and the server was confirmed alive before the frame and dead after.
Impact
Any web page a developer has open — completely unrelated to the site being built — can crash their local eleventy --serve session at will, with zero warning, just by the developer having that page open in another tab. This also means a malicious ad, compromised third-party script, or any attacker-controlled page can deny service to a developer's workflow.
Recommended Fix
- Validate the
Originheader during the WebSocket upgrade/handshake, accepting onlynull/expected local origins (or use theverifyClientoption most WS libraries provide). - Wrap
JSON.parse()in a try/catch and simply ignore/close the connection on malformed input instead of letting the exception propagate.
Verification
Dynamically confirmed on v3.0.0-alpha.11 against a real running server instance with a real cross-origin WebSocket client, as shown above.
- Lingua principale
- JavaScript
- Stelle
- 109
- Fork
- 19
- Merge medio
- 6g 3h
- PR unite (30g)
- 2
Preparare l'ambiente
Questo progetto non fornisce container di sviluppo, Dockerfile né guida per i contributori, quindi l'ambiente è a tuo carico: parti dal suo README e consulta la nostra guida al primo contributo per i passaggi generali.
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di 11ty/dev-server
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
11ty/dev-server#95 ·
-
needs-votes
Difficoltà 4/5 3-5 giorni Idoneità per principianti 35/100
11ty/dev-server#113 · 2 commenti ·
-
enhancement
Difficoltà 5/5 Più di una settimana Idoneità per principianti 25/100
11ty/dev-server#86 · 1 commento ·
-
enhancement needs-votes
Difficoltà 3/5 1-2 giorni Idoneità per principianti 45/100
11ty/dev-server#82 · 4 commenti ·
-
enhancement needs-votes
Difficoltà 3/5 1-2 giorni Idoneità per principianti 45/100
11ty/dev-server#53 · 3 commenti · 2 reazioni ·
Tutte le issue di 11ty/dev-server
Issue simili
-
[aw] Upgrade availableApertaagentic-workflows
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 90/100
githubnext/gh-aw-cao#16599 ·
I maintainer di solito rispondono entro 1 giorno
-
effort:low impact:medium status: auto-triaged UI / Studio
Difficoltà 2/5 1-3 ore Idoneità per principianti 88/100
mastra-ai/mastra#26124 · 2 commenti ·
I maintainer di solito rispondono entro 1 giorno
-
allow igdb.comAperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 61/100
AdguardTeam/HostlistsRegistry#939 ·
I maintainer di solito rispondono entro 1 giorno
-
product / databases
Difficoltà 2/5 1-3 ore Idoneità per principianti 82/100
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
smansfield635-create/smansfield635-create.github.io#5818 · 4 commenti ·
I maintainer di solito rispondono entro 1 giorno