Lucene search

K
nvd[email protected]NVD:CVE-2024-43800
HistorySep 10, 2024 - 3:15 p.m.

CVE-2024-43800

2024-09-1015:15:17
CWE-79
web.nvd.nist.gov
7
serve-static
untrusted user input
redirect
execute untrusted code
patched
version 1.16.0

CVSS3

4.7

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

21.3%

serve-static serves static files. serve-static passes untrusted user input - even after sanitizing it - to redirect() may execute untrusted code. This issue is patched in serve-static 1.16.0.

Affected configurations

Nvd
Node
openjsfserve-staticRange<1.16.0node.js
OR
openjsfserve-staticRange2.0.02.1.0node.js
VendorProductVersionCPE
openjsfserve-static*cpe:2.3:a:openjsf:serve-static:*:*:*:*:*:node.js:*:*

CVSS3

4.7

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

21.3%