Количество 2
Количество 2
CVE-2024-43787
Hono is a Web application framework that provides support for any JavaScript runtime. Hono CSRF middleware can be bypassed using crafted Content-Type header. MIME types are case insensitive, but isRequestedByFormElementRe only matches lower-case. As a result, attacker can bypass csrf middleware using upper-case form-like MIME type. This vulnerability is fixed in 4.5.8.
GHSA-rpfr-3m35-5vx5
Hono CSRF middleware can be bypassed using crafted Content-Type header
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2024-43787 Hono is a Web application framework that provides support for any JavaScript runtime. Hono CSRF middleware can be bypassed using crafted Content-Type header. MIME types are case insensitive, but isRequestedByFormElementRe only matches lower-case. As a result, attacker can bypass csrf middleware using upper-case form-like MIME type. This vulnerability is fixed in 4.5.8. | CVSS3: 5 | 0% Низкий | больше 1 года назад | |
GHSA-rpfr-3m35-5vx5 Hono CSRF middleware can be bypassed using crafted Content-Type header | CVSS3: 5 | 0% Низкий | больше 1 года назад |
Уязвимостей на страницу