Описание
serve-static serves static files. serve-static passes untrusted user input - even after sanitizing it - to redirect() may execute untrusted code. This issue is patched in serve-static 1.16.0.
Уязвимые конфигурации
Одно из
EPSS
5 Medium
CVSS3
4.7 Medium
CVSS3
Дефекты
Связанные уязвимости
serve-static serves static files. serve-static passes untrusted user input - even after sanitizing it - to redirect() may execute untrusted code. This issue is patched in serve-static 1.16.0.
serve-static serves static files. serve-static passes untrusted user input - even after sanitizing it - to redirect() may execute untrusted code. This issue is patched in serve-static 1.16.0.
serve-static affected by template injection that can lead to XSS
serve-static serves static files. serve-static passes untrusted user i ...
serve-static vulnerable to template injection that can lead to XSS
EPSS
5 Medium
CVSS3
4.7 Medium
CVSS3