Логотип exploitDog
product: "express"
Консоль
Логотип exploitDog

exploitDog

product: "express"
Express for Node.js

Express for Node.jsминималистичный и гибкий веб-фреймворк для приложений Node.js

Релизный цикл, информация об уязвимостях

Продукт: Express for Node.js
Вендор: openjsf

График релизов

12345201020112012201320142015201620172018201920202021202220232024202520262027

Недавние уязвимости Express for Node.js

Количество 30

redhat логотип

CVE-2022-24999

около 3 лет назад

qs before 6.10.3, as used in Express before 4.17.3 and other products, allows attackers to cause a Node process hang for an Express application because an __ proto__ key can be used. In many typical Express use cases, an unauthenticated remote attacker can place the attack payload in the query string of the URL that is used to visit the application, such as a[__proto__]=b&a[__proto__]&a[length]=100000000. The fix was backported to qs 6.9.7, 6.8.3, 6.7.3, 6.6.1, 6.5.3, 6.4.1, 6.3.3, and 6.2.4 (and therefore Express 4.17.3, which has "deps: qs@6.9.7" in its release description, is not vulnerable).

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-53r2-gvmc-c45q

больше 3 лет назад

The EXPRESS (aka com.gpshopper.express.android) application 2.5.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

EPSS: Низкий
github логотип

GHSA-6qfg-9c4g-p7cq

почти 4 года назад

The Internet Key Exchange version 1 (IKEv1) implementation in Check Point products allows remote attackers to cause a denial of service via certain crafted IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1. NOTE: due to the lack of details in the advisory, it is unclear which of CVE-2005-3666, CVE-2005-3667, and/or CVE-2005-3668 this issue applies to.

EPSS: Низкий
github логотип

GHSA-gpvr-g6gh-9mc2

больше 7 лет назад

No Charset in Content-Type Header in express

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2014-6393

больше 8 лет назад

The Express web framework before 3.11 and 4.x before 4.5 for Node.js does not provide a charset field in HTTP Content-Type headers in 400 level responses, which might allow remote attackers to conduct cross-site scripting (XSS) attacks via characters in a non-standard encoding.

CVSS3: 6.1
EPSS: Низкий
debian логотип

CVE-2014-6393

больше 8 лет назад

The Express web framework before 3.11 and 4.x before 4.5 for Node.js d ...

CVSS3: 6.1
EPSS: Низкий
ubuntu логотип

CVE-2014-6393

больше 8 лет назад

The Express web framework before 3.11 and 4.x before 4.5 for Node.js does not provide a charset field in HTTP Content-Type headers in 400 level responses, which might allow remote attackers to conduct cross-site scripting (XSS) attacks via characters in a non-standard encoding.

CVSS3: 6.1
EPSS: Низкий
redhat логотип

CVE-2014-6393

почти 11 лет назад

The Express web framework before 3.11 and 4.x before 4.5 for Node.js does not provide a charset field in HTTP Content-Type headers in 400 level responses, which might allow remote attackers to conduct cross-site scripting (XSS) attacks via characters in a non-standard encoding.

CVSS2: 4.3
EPSS: Низкий
nvd логотип

CVE-2014-6887

больше 11 лет назад

The EXPRESS (aka com.gpshopper.express.android) application 2.5.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

CVSS2: 5.4
EPSS: Низкий
nvd логотип

CVE-2005-3673

около 20 лет назад

The Internet Key Exchange version 1 (IKEv1) implementation in Check Point products allows remote attackers to cause a denial of service via certain crafted IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1. NOTE: due to the lack of details in the advisory, it is unclear which of CVE-2005-3666, CVE-2005-3667, and/or CVE-2005-3668 this issue applies to.

CVSS2: 7.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
redhat логотип
CVE-2022-24999

qs before 6.10.3, as used in Express before 4.17.3 and other products, allows attackers to cause a Node process hang for an Express application because an __ proto__ key can be used. In many typical Express use cases, an unauthenticated remote attacker can place the attack payload in the query string of the URL that is used to visit the application, such as a[__proto__]=b&a[__proto__]&a[length]=100000000. The fix was backported to qs 6.9.7, 6.8.3, 6.7.3, 6.6.1, 6.5.3, 6.4.1, 6.3.3, and 6.2.4 (and therefore Express 4.17.3, which has "deps: qs@6.9.7" in its release description, is not vulnerable).

CVSS3: 7.5
1%
Низкий
около 3 лет назад
github логотип
GHSA-53r2-gvmc-c45q

The EXPRESS (aka com.gpshopper.express.android) application 2.5.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

0%
Низкий
больше 3 лет назад
github логотип
GHSA-6qfg-9c4g-p7cq

The Internet Key Exchange version 1 (IKEv1) implementation in Check Point products allows remote attackers to cause a denial of service via certain crafted IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1. NOTE: due to the lack of details in the advisory, it is unclear which of CVE-2005-3666, CVE-2005-3667, and/or CVE-2005-3668 this issue applies to.

9%
Низкий
почти 4 года назад
github логотип
GHSA-gpvr-g6gh-9mc2

No Charset in Content-Type Header in express

CVSS3: 6.1
0%
Низкий
больше 7 лет назад
nvd логотип
CVE-2014-6393

The Express web framework before 3.11 and 4.x before 4.5 for Node.js does not provide a charset field in HTTP Content-Type headers in 400 level responses, which might allow remote attackers to conduct cross-site scripting (XSS) attacks via characters in a non-standard encoding.

CVSS3: 6.1
0%
Низкий
больше 8 лет назад
debian логотип
CVE-2014-6393

The Express web framework before 3.11 and 4.x before 4.5 for Node.js d ...

CVSS3: 6.1
0%
Низкий
больше 8 лет назад
ubuntu логотип
CVE-2014-6393

The Express web framework before 3.11 and 4.x before 4.5 for Node.js does not provide a charset field in HTTP Content-Type headers in 400 level responses, which might allow remote attackers to conduct cross-site scripting (XSS) attacks via characters in a non-standard encoding.

CVSS3: 6.1
0%
Низкий
больше 8 лет назад
redhat логотип
CVE-2014-6393

The Express web framework before 3.11 and 4.x before 4.5 for Node.js does not provide a charset field in HTTP Content-Type headers in 400 level responses, which might allow remote attackers to conduct cross-site scripting (XSS) attacks via characters in a non-standard encoding.

CVSS2: 4.3
0%
Низкий
почти 11 лет назад
nvd логотип
CVE-2014-6887

The EXPRESS (aka com.gpshopper.express.android) application 2.5.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

CVSS2: 5.4
0%
Низкий
больше 11 лет назад
nvd логотип
CVE-2005-3673

The Internet Key Exchange version 1 (IKEv1) implementation in Check Point products allows remote attackers to cause a denial of service via certain crafted IKE packets, as demonstrated by the PROTOS ISAKMP Test Suite for IKEv1. NOTE: due to the lack of details in the advisory, it is unclear which of CVE-2005-3666, CVE-2005-3667, and/or CVE-2005-3668 this issue applies to.

CVSS2: 7.8
9%
Низкий
около 20 лет назад

Уязвимостей на страницу


Поделиться