Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v2v2-hph8-q5xp

Опубликовано: 08 янв. 2024
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

@fastify/reply-from JSON Content-Type parsing confusion

Impact

The main repo of fastify use fast-content-type-parse to parse request Content-Type, which will trim after split.

The fastify-reply-from have not use this repo to unify the parse of Content-Type, which won't trim.

As a result, a reverse proxy server built with @fastify/reply-from could misinterpret the incoming body by passing an header ContentType: application/json ; charset=utf-8. This can lead to bypass of security checks.

Patches

@fastify/reply-from v9.6.0 include the fix.

Workarounds

There are no known workarounds.

References

Hackerone Report: https://hackerone.com/reports/2295770.

Пакеты

Наименование

@fastify/reply-from

npm
Затронутые версииВерсия исправления

< 9.6.0

9.6.0

EPSS

Процентиль: 45%
0.00229
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-444

Связанные уязвимости

CVSS3: 5.3
nvd
около 2 лет назад

fastify-reply-from is a Fastify plugin to forward the current HTTP request to another server. A reverse proxy server built with `@fastify/reply-from` could misinterpret the incoming body by passing an header `ContentType: application/json ; charset=utf-8`. This can lead to bypass of security checks. This vulnerability has been patched in '@fastify/reply-from` version 9.6.0.

EPSS

Процентиль: 45%
0.00229
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-444