Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-45590

Опубликовано: 10 сент. 2024
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

body-parser is Node.js body parsing middleware. body-parser <1.20.3 is vulnerable to denial of service when url encoding is enabled. A malicious actor using a specially crafted payload could flood the server with a large number of requests, resulting in denial of service. This issue is patched in 1.20.3.

A flaw was found in body-parser. This vulnerability causes denial of service via a specially crafted payload when the URL encoding is enabled.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Cryostat 3body-parserAffected
Logging Subsystem for Red Hat OpenShiftopenshift-logging/kibana6-rhel8Not affected
Logging Subsystem for Red Hat OpenShiftopenshift-logging/logging-view-plugin-rhel9Not affected
Migration Toolkit for Applications 7mta/mta-cli-rhel9Will not fix
Migration Toolkit for Applications 7mta/mta-ui-rhel9Will not fix
Migration Toolkit for Runtimesbody-parserAffected
Migration Toolkit for Virtualizationmigration-toolkit-virtualization/mtv-console-plugin-rhel9Not affected
Multicluster Engine for Kubernetesmulticluster-engine/console-mce-rhel8Not affected
Node HealthCheck Operatorworkload-availability/node-remediation-console-rhel8Will not fix
OpenShift Lightspeedopenshift-lightspeed-beta/lightspeed-console-plugin-rhel9Affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-405
https://bugzilla.redhat.com/show_bug.cgi?id=2311171body-parser: Denial of Service Vulnerability in body-parser

EPSS

Процентиль: 84%
0.02072
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 1 года назад

body-parser is Node.js body parsing middleware. body-parser <1.20.3 is vulnerable to denial of service when url encoding is enabled. A malicious actor using a specially crafted payload could flood the server with a large number of requests, resulting in denial of service. This issue is patched in 1.20.3.

CVSS3: 7.5
nvd
больше 1 года назад

body-parser is Node.js body parsing middleware. body-parser <1.20.3 is vulnerable to denial of service when url encoding is enabled. A malicious actor using a specially crafted payload could flood the server with a large number of requests, resulting in denial of service. This issue is patched in 1.20.3.

CVSS3: 7.5
msrc
больше 1 года назад

body-parser vulnerable to denial of service when url encoding is enabled

CVSS3: 7.5
debian
больше 1 года назад

body-parser is Node.js body parsing middleware. body-parser <1.20.3 is ...

CVSS3: 7.5
github
больше 1 года назад

body-parser vulnerable to denial of service when url encoding is enabled

EPSS

Процентиль: 84%
0.02072
Низкий

7.5 High

CVSS3

Уязвимость CVE-2024-45590