Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2024-43799

Опубликовано: 10 сент. 2024
Источник: debian
EPSS Низкий

Описание

Send is a library for streaming files from the file system as a http response. Send passes untrusted user input to SendStream.redirect() which executes untrusted code. This issue is patched in send 0.19.0.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
node-sendfixed1.1.0+~cs1.19.4-1package
node-sendfixed0.18.0+~cs1.19.1-3+deb12u1bookwormpackage

Примечания

  • https://github.com/pillarjs/send/security/advisories/GHSA-m6fv-jmcg-4jfg

  • https://github.com/pillarjs/send/commit/ae4f2989491b392ae2ef3b0015a019770ae65d35 (0.19.0)

EPSS

Процентиль: 31%
0.00118
Низкий

Связанные уязвимости

CVSS3: 5
ubuntu
больше 1 года назад

Send is a library for streaming files from the file system as a http response. Send passes untrusted user input to SendStream.redirect() which executes untrusted code. This issue is patched in send 0.19.0.

CVSS3: 5
redhat
больше 1 года назад

Send is a library for streaming files from the file system as a http response. Send passes untrusted user input to SendStream.redirect() which executes untrusted code. This issue is patched in send 0.19.0.

CVSS3: 5
nvd
больше 1 года назад

Send is a library for streaming files from the file system as a http response. Send passes untrusted user input to SendStream.redirect() which executes untrusted code. This issue is patched in send 0.19.0.

CVSS3: 4.7
msrc
около 1 года назад

send vulnerable to template injection that can lead to XSS

CVSS3: 5
github
больше 1 года назад

send vulnerable to template injection that can lead to XSS

EPSS

Процентиль: 31%
0.00118
Низкий