Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mpcf-4gmh-23w8

Опубликовано: 24 июл. 2018
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Regular Expression Denial of Service in forwarded

Affected versions of forwarded are vulnerable to regular expression denial of service when parsing specially crafted user input.

Recommendation

Update to version 0.1.2 or later

Пакеты

Наименование

forwarded

npm
Затронутые версииВерсия исправления

< 0.1.2

0.1.2

EPSS

Процентиль: 69%
0.006
Низкий

7.5 High

CVSS3

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 7.5
redhat
больше 7 лет назад

The forwarded module is used by the Express.js framework to handle the X-Forwarded-For header. It is vulnerable to a regular expression denial of service when it's passed specially crafted input to parse. This causes the event loop to be blocked causing a denial of service condition.

CVSS3: 7.5
nvd
больше 7 лет назад

The forwarded module is used by the Express.js framework to handle the X-Forwarded-For header. It is vulnerable to a regular expression denial of service when it's passed specially crafted input to parse. This causes the event loop to be blocked causing a denial of service condition.

EPSS

Процентиль: 69%
0.006
Низкий

7.5 High

CVSS3

Дефекты

CWE-400