Cross-origin unauthenticated WebSocket DoS: no Origin check + unhandled JSON.parse crashes the server
还没有人认领这个 Issue。
评估
- 难度
- 4/5
- 预计耗时
- 3-5 天
- 新手友好度
- 48/100
- Issue 类型
- 缺陷
- 描述清晰度
- 基本清楚
- 活跃度
- 活跃
- 技术栈
- javascript
调研方向
从 server.js 中 1002-1003 行附近的 setupReloadNotifier 开始,然后检查 updateServer 连接处理程序及其 WebSocket 握手处理。复现 issue 中的 malformed-frame 情况,并跟踪已接受的 Origin 标头。当不受信任的 origin 按照项目的 local-origin policy 进行处理,且 malformed message 不再终止 server 时,即表示完成。
由索引模型根据 Issue 内容生成。
描述
Summary
The live-reload WebSocket server accepts connections from any origin (no Origin header validation during the handshake), and its message handler calls JSON.parse() on incoming frames with no try/catch. Any web page — including a malicious third-party site a developer merely has open in another browser tab while running eleventy --serve — can open a cross-origin WebSocket to the dev server and send one non-JSON frame to crash the entire process.
CWE: CWE-346 (Origin Validation Error) + CWE-248 (Uncaught Exception)
Severity: High
CVSS: 8.1 — CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:N/A:H
Root Cause
server.js (setupReloadNotifier's WebSocket connection handler), around line 1002-1003:
ws.on("message", (data) => {
let parsed = JSON.parse(data.toString()); // no try/catch
...
updateServer.on("connection", ...) never inspects the handshake Origin header before accepting the WebSocket connection, so the classic "malicious webpage attacks your localhost dev server" pattern (the same class of bug behind several historical webpack-dev-server DNS-rebinding/cross-origin advisories) applies here directly.
Reproduction
With the dev server running (see companion issue #150 for setup), from a separate script simulating a cross-origin page:
const ws = new WebSocket("ws://localhost:PORT", { headers: { Origin: "http://evil.example.com" } });
ws.on("open", () => ws.send("NOT-VALID-JSON{{{"));
Server log:
SyntaxError: Unexpected token 'N', "NOT-VALID-JSON{{{" is not valid JSON
at server.js:1003:27
Node.js v22.23.2 [process exits]
Verified: the connection was accepted despite the spoofed Origin header, and the server was confirmed alive before the frame and dead after.
Impact
Any web page a developer has open — completely unrelated to the site being built — can crash their local eleventy --serve session at will, with zero warning, just by the developer having that page open in another tab. This also means a malicious ad, compromised third-party script, or any attacker-controlled page can deny service to a developer's workflow.
Recommended Fix
- Validate the
Originheader during the WebSocket upgrade/handshake, accepting onlynull/expected local origins (or use theverifyClientoption most WS libraries provide). - Wrap
JSON.parse()in a try/catch and simply ignore/close the connection on malformed input instead of letting the exception propagate.
Verification
Dynamically confirmed on v3.0.0-alpha.11 against a real running server instance with a real cross-origin WebSocket client, as shown above.
- 主要语言
- JavaScript
- 星标
- 109
- 派生
- 19
- 平均合并
- 6 天 3 小时
- 30 天内合并 PR
- 2
环境准备
这个项目没有提供开发容器、Dockerfile 或贡献指南,环境需要你自己搭建:先看它的 README,通用步骤见我们的新手贡献指南。
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
11ty/dev-server 的其他 Issue
-
难度 2/5 1-3 小时 新手友好度 68/100
11ty/dev-server#95 ·
-
needs-votes
难度 4/5 3-5 天 新手友好度 35/100
11ty/dev-server#113 · 2 条评论 ·
-
enhancement
难度 5/5 一周以上 新手友好度 25/100
11ty/dev-server#86 · 1 条评论 ·
-
enhancement needs-votes
难度 3/5 1-2 天 新手友好度 45/100
11ty/dev-server#82 · 4 条评论 ·
-
enhancement needs-votes
难度 3/5 1-2 天 新手友好度 45/100
11ty/dev-server#53 · 3 条评论 · 2 个 reaction ·
相似的 Issue
-
难度 2/5 1 小时以内 新手友好度 85/100
capricorn86/happy-dom#2474 ·
维护者通常 2 天内回复
-
bug
难度 2/5 1-3 小时 新手友好度 90/100
juice-shop/juice-shop#3662 ·
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 70/100
-
Add unit-test coverage for API URL resolution and device authentication error handling可能已有人在做 @Simranjit8933 今天认领。 未关闭
难度 2/5 1-3 小时 新手友好度 90/100
fossasia/eventyay-checkin#170 · 1 条评论 ·
维护者通常 1 天内回复
-
难度 2/5 1-3 小时 新手友好度 75/100
维护者通常 1 天内回复