Количество 3
Количество 3
CVE-2017-16136
method-override is a module used by the Express.js framework to let you use HTTP verbs such as PUT or DELETE in places where the client doesn't support it. method-override is vulnerable to a regular expression denial of service vulnerability when specially crafted input is passed in to be parsed via the X-HTTP-Method-Override header.
CVE-2017-16136
method-override is a module used by the Express.js framework to let you use HTTP verbs such as PUT or DELETE in places where the client doesn't support it. method-override is vulnerable to a regular expression denial of service vulnerability when specially crafted input is passed in to be parsed via the X-HTTP-Method-Override header.
GHSA-qx2f-477c-35rq
method-override ReDoS when untrusted user input passed into X-HTTP-Method-Override header
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2017-16136 method-override is a module used by the Express.js framework to let you use HTTP verbs such as PUT or DELETE in places where the client doesn't support it. method-override is vulnerable to a regular expression denial of service vulnerability when specially crafted input is passed in to be parsed via the X-HTTP-Method-Override header. | CVSS3: 5.3 | 0% Низкий | больше 8 лет назад | |
CVE-2017-16136 method-override is a module used by the Express.js framework to let you use HTTP verbs such as PUT or DELETE in places where the client doesn't support it. method-override is vulnerable to a regular expression denial of service vulnerability when specially crafted input is passed in to be parsed via the X-HTTP-Method-Override header. | CVSS3: 7.5 | 0% Низкий | больше 7 лет назад | |
GHSA-qx2f-477c-35rq method-override ReDoS when untrusted user input passed into X-HTTP-Method-Override header | CVSS3: 7.5 | 0% Низкий | больше 7 лет назад |
Уязвимостей на страницу