Описание
The got package before 12.1.0 (also fixed in 11.8.5) for Node.js allows a redirect to a UNIX socket.
Пакеты
Пакет | Статус | Версия исправления | Релиз | Тип |
---|---|---|---|---|
node-got | fixed | 11.8.3+~cs58.7.37-3 | package | |
node-got | fixed | 11.8.1+~cs53.13.17-3+deb11u1 | bullseye | package |
node-got | not-affected | buster | package |
Примечания
https://github.com/sindresorhus/got/pull/2047
Fixed by: https://github.com/sindresorhus/got/commit/861ccd9ac2237df762a9e2beed7edd88c60782dc (v12.1.0)
buster tested against CVE here https://salsa.debian.org/js-team/node-got/-/commit/47a15e189e39c29281532131675a998e1c0a9f8e
EPSS
Процентиль: 72%
0.00734
Низкий
Связанные уязвимости
CVSS3: 5.3
ubuntu
около 3 лет назад
The got package before 12.1.0 (also fixed in 11.8.5) for Node.js allows a redirect to a UNIX socket.
CVSS3: 5.3
redhat
около 3 лет назад
The got package before 12.1.0 (also fixed in 11.8.5) for Node.js allows a redirect to a UNIX socket.
CVSS3: 5.3
nvd
около 3 лет назад
The got package before 12.1.0 (also fixed in 11.8.5) for Node.js allows a redirect to a UNIX socket.
EPSS
Процентиль: 72%
0.00734
Низкий