Описание
fastify is a fast and low overhead web framework, for Node.js. Affected versions of fastify are subject to a denial of service via malicious use of the Content-Type header. An attacker can send an invalid Content-Type header that can cause the application to crash. This issue has been addressed in commit fbb07e8d and will be included in release version 4.8.1. Users are advised to upgrade. Users unable to upgrade may manually filter out http content with malicious Content-Type headers.
Ссылки
- PatchThird Party Advisory
- MitigationThird Party Advisory
- Third Party Advisory
- PatchThird Party Advisory
- MitigationThird Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 4.8.1 (исключая)
cpe:2.3:a:fastify:fastify:*:*:*:*:*:node.js:*:*
EPSS
Процентиль: 86%
0.03001
Низкий
7.5 High
CVSS3
Дефекты
CWE-754
Связанные уязвимости
CVSS3: 7.5
github
больше 3 лет назад
fastify vulnerable to denial of service via malicious Content-Type
EPSS
Процентиль: 86%
0.03001
Низкий
7.5 High
CVSS3
Дефекты
CWE-754