-
Notifications
You must be signed in to change notification settings - Fork 5.2k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
update Sockjs 0.3.20 to fix ERR_STREAM_WRITE_AFTER_END #11076
Comments
This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs. Thank you for your contributions. |
We experienced denial of service because of this. I have created a proof of concept exploit code which you can test on your own Meteor server running SockJS 0.3.19 to instantly crash the container in 3 requests: https://github.com/andsnw/sockjs-dos-py Disclosed to Snyk advisory as well: https://snyk.io/vuln/SNYK-JS-SOCKJS-575261 |
@StorytellerCZ Yes, #11110 fixes the issue that @andsnw mentioned. |
Just saw this same error in our Galaxy logs over the weekend on July 3rd. Looks like It crashed three out of six containers at the exact same time. Got complaints. Running Meteor 1.9.3. Guess we should probably update. |
Fix #11076 by updating ddp dependencies
ddp-server@2.3.2 is published now. |
…ates Fix meteor#11076 by updating ddp dependencies
…ates Fix meteor#11076 by updating ddp dependencies
On our server sometime we have error's about ERR_STREAM_WRITE_AFTER_END
Here the stack
After a few search it seems to be this bug in SockJS sockjs/sockjs-node#252 and that have been fixed in 0.3.20
On ubuntu LTS
Meteor: 1.10.2
Node: 12.16.1
The text was updated successfully, but these errors were encountered: