npm安装hitbtc-api后遇ws包DoS漏洞,寻求解决方案
Let's walk through how to resolve this high-severity Denial of Service (DoS) vulnerability in the ws package that's a nested dependency of hitbtc-api-node.
Quick Fix Options
Option 1: Use npm's Built-in Audit Fix
First, try the simplest approach to let npm automatically patch the vulnerable dependency:
npm audit fix
This will attempt to upgrade ws to the minimum safe version (>=3.3.1) if the dependency constraints of hitbtc-api-node allow it.
Option 2: Force Resolution (If Automatic Fix Fails)
If npm audit fix doesn't work (because hitbtc-api-node might have a locked version range for ws), use npm-force-resolutions to override the nested dependency version:
- Install the resolution tool as a dev dependency:
npm install --save-dev npm-force-resolutions - Add a
resolutionsfield to yourpackage.jsonto enforce the safewsversion:"resolutions": { "ws": "^3.3.1" } - Add a
preinstallscript to yourpackage.jsonto run the resolution before installing dependencies:"scripts": { "preinstall": "npx npm-force-resolutions" } - Reinstall your dependencies to apply the fix:
npm install
Vulnerability Details
Overview
The vulnerable versions of ws will crash when receiving a malicious Sec-WebSocket-Extensions request header that uses Object.prototype property names (like constructor) as extension or parameter names.
Proof of Concept Code
Here's the test code that demonstrates the crash:
const WebSocket = require('ws'); const net = require('net'); const wss = new WebSocket.Server({ port: 3000 }, function () { const payload = 'constructor'; // or ',;constructor' const request = [ 'GET / HTTP/1.1', 'Connection: Upgrade', 'Sec-WebSocket-Key: test', 'Sec-WebSocket-Version: 8', `Sec-WebSocket-Extensions: ${payload}`, 'Upgrade: websocket', '' ].join('\n'); const socket = net.connect(3000, function () { socket.resume(); socket.write(request); }); });
Root Cause & Fix
The issue stems from improper handling of prototype pollution in the header parsing logic of older ws versions. Upgrading ws to version 3.3.1 or higher patches this parsing flaw, preventing the crash from malicious requests.
内容的提问来源于stack exchange,提问作者Irfan Muhammad

