Potential Phoenix Framework Presence Client Vulnerability
An early warning has been issued regarding a potential vulnerability in the Phoenix Framework's Presence JavaScript client. This vulnerability, reportedly affecting versions <1.5.15, <1.6.17, <1.7.24, and <1.8.9, may allow an attacker with ordinary channel access to cause a persistent client-side denial of service against every viewer of a presence channel topic.
What happened
The issue reportedly arises from presence keys colliding with JavaScript Object.prototype member names, leading to crashes in the Presence.syncState/syncDiff functions. This improper check for unusual or exceptional conditions is under investigation.
To assess your exposure, verify if your project utilizes the affected versions of the Phoenix Framework's Presence JavaScript client. If so, it is recommended to reject or sanitize presence keys that may collide with Object.prototype member names.
For more detailed information, consult the primary sources. The severity of this potential vulnerability is high, and further updates will be provided as more information becomes available.
How 0Day mitigates this
phoenixframework phoenix is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.