Описание
Prototype Pollution in express-fileupload
This affects the package express-fileupload before 1.1.8. If the parseNested option is enabled, sending a corrupt HTTP request can lead to denial of service or arbitrary code execution.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2020-7699
- https://github.com/richardgirges/express-fileupload/issues/236
- https://github.com/richardgirges/express-fileupload/pull/237
- https://github.com/richardgirges/express-fileupload/commit/db495357d7557ceb5c034de91a7a574bd12f9b9f
- https://security.netapp.com/advisory/ntap-20200821-0003
- https://snyk.io/vuln/SNYK-JS-EXPRESSFILEUPLOAD-595969
Пакеты
Наименование
express-fileupload
npm
Затронутые версииВерсия исправления
< 1.1.9
1.1.9
Связанные уязвимости
CVSS3: 7.5
nvd
больше 5 лет назад
This affects the package express-fileupload before 1.1.8. If the parseNested option is enabled, sending a corrupt HTTP request can lead to denial of service or arbitrary code execution.