Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-16136

Опубликовано: 27 сент. 2017
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

method-override is a module used by the Express.js framework to let you use HTTP verbs such as PUT or DELETE in places where the client doesn't support it. method-override is vulnerable to a regular expression denial of service vulnerability when specially crafted input is passed in to be parsed via the X-HTTP-Method-Override header.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Mobile Application Platform 4fh-nguiNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=1500711nodejs-method-override: Regular expression Denial of Service

EPSS

Процентиль: 55%
0.00328
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
больше 7 лет назад

method-override is a module used by the Express.js framework to let you use HTTP verbs such as PUT or DELETE in places where the client doesn't support it. method-override is vulnerable to a regular expression denial of service vulnerability when specially crafted input is passed in to be parsed via the X-HTTP-Method-Override header.

CVSS3: 7.5
github
больше 7 лет назад

method-override ReDoS when untrusted user input passed into X-HTTP-Method-Override header

EPSS

Процентиль: 55%
0.00328
Низкий

5.3 Medium

CVSS3