Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rch9-xh7r-mqgw

Опубликовано: 26 июл. 2018
Источник: github
Github: Прошло ревью
CVSS3: 5.4

Описание

Cross-Site Scripting in connect

connect node module before 2.14.0 suffers from a Cross-Site Scripting (XSS) vulnerability due to a lack of validation of file in directory.js middleware.

Пакеты

Наименование

connect

npm
Затронутые версииВерсия исправления

< 2.14.0

2.14.0

EPSS

Процентиль: 56%
0.00339
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
ubuntu
больше 7 лет назад

connect node module before 2.14.0 suffers from a Cross-Site Scripting (XSS) vulnerability due to a lack of validation of file in directory.js middleware.

CVSS3: 6.4
redhat
больше 7 лет назад

connect node module before 2.14.0 suffers from a Cross-Site Scripting (XSS) vulnerability due to a lack of validation of file in directory.js middleware.

CVSS3: 5.4
nvd
больше 7 лет назад

connect node module before 2.14.0 suffers from a Cross-Site Scripting (XSS) vulnerability due to a lack of validation of file in directory.js middleware.

CVSS3: 5.4
debian
больше 7 лет назад

connect node module before 2.14.0 suffers from a Cross-Site Scripting ...

EPSS

Процентиль: 56%
0.00339
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79