← Back

CVE-2024-43796

nvd nist
Published: Sep 10, 2024Modified: Sep 20, 2024

JSON object

Loading...
4.7
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 1.6 / Impact: 2.7
Source: NVD

Description

Express.js minimalist web framework for node. In express < 4.20.0, passing untrusted user input - even after sanitizing it - to response.redirect() may execute untrusted code. This issue is patched in express 4.20.0.

Affected (12)

Products: Openjsf: Express
1 product
Express
Configuration A
12 vulnerable
Vulnerable SoftwareAffected Versions
Openjsf
Before 4.20.0
Version 5.0.0 alpha1
Version 5.0.0 alpha2
Version 5.0.0 alpha3
Version 5.0.0 alpha4
Version 5.0.0 alpha5
Version 5.0.0 alpha6
Version 5.0.0 alpha7
Version 5.0.0 alpha8
Version 5.0.0 beta1
Version 5.0.0 beta2
Version 5.0.0 beta3

References (2)

Timeline

No history available yet.