Lucene search

K
osvGoogleOSV:GHSA-GPVR-G6GH-9MC2
HistoryOct 23, 2018 - 5:22 p.m.

No Charset in Content-Type Header in express

2018-10-2317:22:54
Google
osv.dev
14

EPSS

0.001

Percentile

30.9%

Vulnerable versions of express do not specify a charset field in the content-type header while displaying 400 level response messages. The lack of enforcing user’s browser to set correct charset, could be leveraged by an attacker to perform a cross-site scripting attack, using non-standard encodings, like UTF-7.

Recommendation

For express 3.x, update express to version 3.11 or later.
For express 4.x, update express to version 4.5 or later.

EPSS

0.001

Percentile

30.9%