Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-34350

Опубликовано: 14 мая 2024
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

Next.js is a React framework that can provide building blocks to create web applications. Prior to 13.5.1, an inconsistent interpretation of a crafted HTTP request meant that requests are treated as both a single request, and two separate requests by Next.js, leading to desynchronized responses. This led to a response queue poisoning vulnerability in the affected Next.js versions. For a request to be exploitable, the affected route also had to be making use of the rewrites feature in Next.js. The vulnerability is resolved in Next.js 13.5.1 and newer.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:vercel:next.js:*:*:*:*:*:node.js:*:*
Версия от 13.4.0 (включая) до 13.5.1 (исключая)

EPSS

Процентиль: 70%
0.00635
Низкий

7.5 High

CVSS3

Дефекты

CWE-444

Связанные уязвимости

CVSS3: 7.5
github
больше 1 года назад

Next.js Vulnerable to HTTP Request Smuggling

EPSS

Процентиль: 70%
0.00635
Низкий

7.5 High

CVSS3

Дефекты

CWE-444