Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-9266

Опубликовано: 03 окт. 2024
Источник: redhat
CVSS3: 6.1
EPSS Низкий

Описание

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Express. This vulnerability affects the use of the Express Response object. This issue impacts Express: from 3.4.5 before 4.0.0.

A flaw was found in the Express package for Node.js. Certain versions are vulnerable to an open redirect attack, a URL redirection to an untrusted site, via the Express 3 Response object. This flaw may allow a user to be redirected to an untrusted page containing malware, which may compromise the user's machine.

Отчет

This flaw is specific to certain versions of Express 3, which has reached end-of-life. No Red Hat products are affected by this vulnerability.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
A-MQ Interconnect 1qpid-dispatchNot affected
Cryostat 3expressNot affected
Logging Subsystem for Red Hat OpenShiftopenshift-logging/logging-view-plugin-rhel9Not affected
Migration Toolkit for Applications 7mta/mta-cli-rhel9Not affected
Migration Toolkit for Applications 7mta/mta-ui-rhel9Not affected
Migration Toolkit for Containersrhmtc/openshift-migration-ui-rhel8Not affected
Migration Toolkit for Virtualizationmigration-toolkit-virtualization/mtv-console-plugin-rhel9Not affected
Multicluster Engine for Kubernetesmulticluster-engine/console-mce-rhel8Not affected
Network Observability Operatornetwork-observability/network-observability-console-plugin-rhel9Not affected
Node HealthCheck Operatorworkload-availability/node-remediation-console-rhel8Not affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-601
https://bugzilla.redhat.com/show_bug.cgi?id=2316353express: URL redirection vulnerability

EPSS

Процентиль: 26%
0.00092
Низкий

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.7
ubuntu
около 1 года назад

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Express. This vulnerability affects the use of the Express Response object. This issue impacts Express: from 3.4.5 before 4.0.0.

CVSS3: 4.7
nvd
около 1 года назад

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Express. This vulnerability affects the use of the Express Response object. This issue impacts Express: from 3.4.5 before 4.0.0.

CVSS3: 4.7
debian
около 1 года назад

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in E ...

CVSS3: 4.7
github
около 1 года назад

Express Open Redirect vulnerability

EPSS

Процентиль: 26%
0.00092
Низкий

6.1 Medium

CVSS3