Lucene search

K
nvd[email protected]NVD:CVE-2024-43796
HistorySep 10, 2024 - 3:15 p.m.

CVE-2024-43796

2024-09-1015:15:17
CWE-79
web.nvd.nist.gov
8
cve-2024-43796
express.js
web framework
untrusted input
response.redirect()
code execution

CVSS3

4.7

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

17.7%

Express.js minimalist web framework for node. In express < 4.20.0, passing untrusted user input - even after sanitizing it - to response.redirect() may execute untrusted code. This issue is patched in express 4.20.0.

Affected configurations

Nvd
Node
openjsfexpressRange<4.20.0node.js
OR
openjsfexpressMatch5.0.0alpha1node.js
OR
openjsfexpressMatch5.0.0alpha2node.js
OR
openjsfexpressMatch5.0.0alpha3node.js
OR
openjsfexpressMatch5.0.0alpha4node.js
OR
openjsfexpressMatch5.0.0alpha5node.js
OR
openjsfexpressMatch5.0.0alpha6node.js
OR
openjsfexpressMatch5.0.0alpha7node.js
OR
openjsfexpressMatch5.0.0alpha8node.js
OR
openjsfexpressMatch5.0.0beta1node.js
OR
openjsfexpressMatch5.0.0beta2node.js
OR
openjsfexpressMatch5.0.0beta3node.js
VendorProductVersionCPE
openjsfexpress*cpe:2.3:a:openjsf:express:*:*:*:*:*:node.js:*:*
openjsfexpress5.0.0cpe:2.3:a:openjsf:express:5.0.0:alpha1:*:*:*:node.js:*:*
openjsfexpress5.0.0cpe:2.3:a:openjsf:express:5.0.0:alpha2:*:*:*:node.js:*:*
openjsfexpress5.0.0cpe:2.3:a:openjsf:express:5.0.0:alpha3:*:*:*:node.js:*:*
openjsfexpress5.0.0cpe:2.3:a:openjsf:express:5.0.0:alpha4:*:*:*:node.js:*:*
openjsfexpress5.0.0cpe:2.3:a:openjsf:express:5.0.0:alpha5:*:*:*:node.js:*:*
openjsfexpress5.0.0cpe:2.3:a:openjsf:express:5.0.0:alpha6:*:*:*:node.js:*:*
openjsfexpress5.0.0cpe:2.3:a:openjsf:express:5.0.0:alpha7:*:*:*:node.js:*:*
openjsfexpress5.0.0cpe:2.3:a:openjsf:express:5.0.0:alpha8:*:*:*:node.js:*:*
openjsfexpress5.0.0cpe:2.3:a:openjsf:express:5.0.0:beta1:*:*:*:node.js:*:*
Rows per page:
1-10 of 121

CVSS3

4.7

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

17.7%