Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-10491

Опубликовано: 29 окт. 2024
Источник: nvd
CVSS3: 4
CVSS3: 5.3
EPSS Низкий

Описание

A vulnerability has been identified in the Express response.links function, allowing for arbitrary resource injection in the Link header when unsanitized data is used.

The issue arises from improper sanitization in Link header values, which can allow a combination of characters like ,, ;, and <> to preload malicious resources.

This vulnerability is especially relevant for dynamic parameters.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:openjsf:express:*:*:*:*:*:node.js:*:*
Версия до 3.21.4 (включая)

EPSS

Процентиль: 8%
0.00033
Низкий

4 Medium

CVSS3

5.3 Medium

CVSS3

Дефекты

CWE-74
NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 4
ubuntu
8 месяцев назад

A vulnerability has been identified in the Express response.links function, allowing for arbitrary resource injection in the Link header when unsanitized data is used. The issue arises from improper sanitization in `Link` header values, which can allow a combination of characters like `,`, `;`, and `<>` to preload malicious resources. This vulnerability is especially relevant for dynamic parameters.

CVSS3: 5.4
redhat
8 месяцев назад

A vulnerability has been identified in the Express response.links function, allowing for arbitrary resource injection in the Link header when unsanitized data is used. The issue arises from improper sanitization in `Link` header values, which can allow a combination of characters like `,`, `;`, and `<>` to preload malicious resources. This vulnerability is especially relevant for dynamic parameters.

CVSS3: 4
debian
8 месяцев назад

A vulnerability has been identified in the Express response.linksfunct ...

CVSS3: 4
github
8 месяцев назад

Express ressource injection

EPSS

Процентиль: 8%
0.00033
Низкий

4 Medium

CVSS3

5.3 Medium

CVSS3

Дефекты

CWE-74
NVD-CWE-noinfo