You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
*For some transitive vulnerabilities, there is no version of direct dependency with a fix. Check the "Details" section below to see if there is a version of transitive dependency where vulnerability is fixed.
**In some cases, Remediation PR cannot be created automatically for a vulnerability despite the availability of remediation
Path to dependency file: /tmp/ws-scm/Notes/Application/package.json
Path to vulnerable library: /tmp/ws-scm/Notes/Application/package.json
Dependency Hierarchy:
sails-1.5.6.tgz (Root Library)
router-1.3.2.tgz
❌ path-to-regexp-0.1.7.tgz (Vulnerable Library)
Found in base branch: master
Vulnerability Details
path-to-regexp turns path strings into a regular expressions. In certain cases, path-to-regexp will output a regular expression that can be exploited to cause poor performance. The regular expression that is vulnerable to backtracking can be generated in the 0.1.x release of path-to-regexp. Upgrade to 0.1.12. This vulnerability exists because of an incomplete fix for CVE-2024-45296.
Path to dependency file: /tmp/ws-scm/Notes/Application/package.json
Path to vulnerable library: /tmp/ws-scm/Notes/Application/package.json
Dependency Hierarchy:
sails-1.5.6.tgz (Root Library)
express-4.17.3.tgz
❌ body-parser-1.19.2.tgz (Vulnerable Library)
Found in base branch: master
Vulnerability Details
body-parser is Node.js body parsing middleware. body-parser <1.20.3 is vulnerable to denial of service when url encoding is enabled. A malicious actor using a specially crafted payload could flood the server with a large number of requests, resulting in denial of service. This issue is patched in 1.20.3.
Path to dependency file: /tmp/ws-scm/Notes/Application/package.json
Path to vulnerable library: /tmp/ws-scm/Notes/Application/package.json
Dependency Hierarchy:
sails-1.5.6.tgz (Root Library)
❌ path-to-regexp-1.5.3.tgz (Vulnerable Library)
Found in base branch: master
Vulnerability Details
path-to-regexp turns path strings into a regular expressions. In certain cases, path-to-regexp will output a regular expression that can be exploited to cause poor performance. Because JavaScript is single threaded and regex matching runs on the main thread, poor performance will block the event loop and lead to a DoS. The bad regular expression is generated any time you have two parameters within a single segment, separated by something that is not a period (.). For users of 0.1, upgrade to 0.1.10. All other users should upgrade to 8.0.0.
Path to dependency file: /tmp/ws-scm/Notes/Application/package.json
Path to vulnerable library: /tmp/ws-scm/Notes/Application/package.json
Dependency Hierarchy:
sails-1.5.6.tgz (Root Library)
sails-generate-2.0.8.tgz
❌ cross-spawn-4.0.2.tgz (Vulnerable Library)
Found in base branch: master
Vulnerability Details
Versions of the package cross-spawn before 7.0.5 are vulnerable to Regular Expression Denial of Service (ReDoS) due to improper input sanitization. An attacker can increase the CPU usage and crash the program by crafting a very large and well crafted string.
Path to dependency file: /tmp/ws-scm/Notes/Application/package.json
Path to vulnerable library: /tmp/ws-scm/Notes/Application/package.json
Dependency Hierarchy:
❌ sails-1.5.6.tgz (Vulnerable Library)
Found in base branch: master
Vulnerability Details
Sails is a realtime MVC Framework for Node.js. In Sails apps prior to version 1.5.7,, an attacker can send a virtual request that will cause the node process to crash. This behavior was fixed in Sails v1.5.7. As a workaround, disable the sockets hook and remove the sails.io.js client.
Path to dependency file: /tmp/ws-scm/Notes/Application/package.json
Path to vulnerable library: /tmp/ws-scm/Notes/Application/package.json
Dependency Hierarchy:
sails-1.5.6.tgz (Root Library)
❌ express-4.17.3.tgz (Vulnerable Library)
Found in base branch: master
Vulnerability Details
Express.js minimalist web framework for node. Versions of Express.js prior to 4.19.0 and all pre-release alpha and beta versions of 5.0 are affected by an open redirect vulnerability using malformed URLs. When a user of Express performs a redirect using a user-provided URL Express performs an encode using encodeurl on the contents before passing it to the location header. This can cause malformed URLs to be evaluated in unexpected ways by common redirect allow list implementations in Express applications, leading to an Open Redirect via bypass of a properly implemented allow list. The main method impacted is res.location() but this is also called from within res.redirect(). The vulnerability is fixed in 4.19.2 and 5.0.0-beta.3.
Path to dependency file: /tmp/ws-scm/Notes/Application/package.json
Path to vulnerable library: /tmp/ws-scm/Notes/Application/package.json
Dependency Hierarchy:
sails-1.5.6.tgz (Root Library)
express-4.17.3.tgz
❌ cookie-0.4.2.tgz (Vulnerable Library)
Found in base branch: master
Vulnerability Details
cookie is a basic HTTP cookie parser and serializer for HTTP servers. The cookie name could be used to set other fields of the cookie, resulting in an unexpected cookie value. A similar escape can be used for path and domain, which could be abused to alter other fields of the cookie. Upgrade to 0.7.0, which updates the validation for name, path, and domain.
Path to dependency file: /tmp/ws-scm/Notes/Application/package.json
Path to vulnerable library: /tmp/ws-scm/Notes/Application/package.json
Dependency Hierarchy:
sails-1.5.6.tgz (Root Library)
❌ semver-4.3.6.tgz (Vulnerable Library)
Found in base branch: master
Vulnerability Details
Versions of the package semver before 7.5.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the function new Range, when untrusted user data is provided as a range.
Path to dependency file: /tmp/ws-scm/Notes/Application/package.json
Path to vulnerable library: /tmp/ws-scm/Notes/Application/package.json
Dependency Hierarchy:
sails-1.5.6.tgz (Root Library)
❌ serve-static-1.13.1.tgz (Vulnerable Library)
Found in base branch: master
Vulnerability Details
serve-static serves static files. serve-static passes untrusted user input - even after sanitizing it - to redirect() may execute untrusted code. This issue is patched in serve-static 1.16.0.
Path to dependency file: /tmp/ws-scm/Notes/Application/package.json
Path to vulnerable library: /tmp/ws-scm/Notes/Application/package.json
Dependency Hierarchy:
sails-1.5.6.tgz (Root Library)
serve-static-1.13.1.tgz
❌ send-0.16.1.tgz (Vulnerable Library)
Found in base branch: master
Vulnerability Details
Send is a library for streaming files from the file system as a http response. Send passes untrusted user input to SendStream.redirect() which executes untrusted code. This issue is patched in send 0.19.0.
Path to dependency file: /tmp/ws-scm/Notes/Application/package.json
Path to vulnerable library: /tmp/ws-scm/Notes/Application/package.json
Dependency Hierarchy:
sails-1.5.6.tgz (Root Library)
❌ express-4.17.3.tgz (Vulnerable Library)
Found in base branch: master
Vulnerability Details
Express.js minimalist web framework for node. In express < 4.20.0, passing untrusted user input - even after sanitizing it - to response.redirect() may execute untrusted code. This issue is patched in express 4.20.0.
mend-bolt-for-githubbot
changed the title
sails-1.5.6.tgz: 4 vulnerabilities (highest severity is: 8.8)
sails-1.5.6.tgz: 5 vulnerabilities (highest severity is: 8.8)
Jul 2, 2024
mend-bolt-for-githubbot
changed the title
sails-1.5.6.tgz: 5 vulnerabilities (highest severity is: 8.8)
sails-1.5.6.tgz: 4 vulnerabilities (highest severity is: 8.8)
Aug 2, 2024
mend-bolt-for-githubbot
changed the title
sails-1.5.6.tgz: 4 vulnerabilities (highest severity is: 8.8)
sails-1.5.6.tgz: 5 vulnerabilities (highest severity is: 8.8)
Sep 11, 2024
mend-bolt-for-githubbot
changed the title
sails-1.5.6.tgz: 5 vulnerabilities (highest severity is: 8.8)
sails-1.5.6.tgz: 6 vulnerabilities (highest severity is: 8.8)
Sep 15, 2024
mend-bolt-for-githubbot
changed the title
sails-1.5.6.tgz: 6 vulnerabilities (highest severity is: 8.8)
sails-1.5.6.tgz: 8 vulnerabilities (highest severity is: 8.8)
Sep 16, 2024
mend-bolt-for-githubbot
changed the title
sails-1.5.6.tgz: 8 vulnerabilities (highest severity is: 8.8)
sails-1.5.6.tgz: 9 vulnerabilities (highest severity is: 8.8)
Sep 16, 2024
mend-bolt-for-githubbot
changed the title
sails-1.5.6.tgz: 9 vulnerabilities (highest severity is: 8.8)
sails-1.5.6.tgz: 10 vulnerabilities (highest severity is: 8.8)
Oct 6, 2024
mend-bolt-for-githubbot
changed the title
sails-1.5.6.tgz: 10 vulnerabilities (highest severity is: 8.8)
sails-1.5.6.tgz: 11 vulnerabilities (highest severity is: 8.8)
Nov 11, 2024
mend-bolt-for-githubbot
changed the title
sails-1.5.6.tgz: 11 vulnerabilities (highest severity is: 8.8)
sails-1.5.6.tgz: 12 vulnerabilities (highest severity is: 8.8)
Dec 6, 2024
Library home page: https://registry.npmjs.org/sails/-/sails-1.5.6.tgz
Path to dependency file: /tmp/ws-scm/Notes/Application/package.json
Path to vulnerable library: /tmp/ws-scm/Notes/Application/package.json
Vulnerabilities
*For some transitive vulnerabilities, there is no version of direct dependency with a fix. Check the "Details" section below to see if there is a version of transitive dependency where vulnerability is fixed.
**In some cases, Remediation PR cannot be created automatically for a vulnerability despite the availability of remediation
Details
Vulnerable Library - ejs-3.1.7.tgz
Embedded JavaScript templates
Library home page: https://registry.npmjs.org/ejs/-/ejs-3.1.7.tgz
Path to dependency file: /tmp/ws-scm/Notes/Application/package.json
Path to vulnerable library: /tmp/ws-scm/Notes/Application/package.json
Dependency Hierarchy:
Found in base branch: master
Vulnerability Details
The ejs (aka Embedded JavaScript templates) package before 3.1.10 for Node.js lacks certain pollution protection.
Publish Date: 2024-04-28
URL: CVE-2024-33883
CVSS 3 Score Details (8.8)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Origin: https://www.cve.org/CVERecord?id=CVE-2024-33883
Release Date: 2024-04-28
Fix Resolution: ejs - 3.1.10
Step up your Open Source Security Game with Mend here
Vulnerable Library - path-to-regexp-0.1.7.tgz
Express style path to RegExp utility
Library home page: https://registry.npmjs.org/path-to-regexp/-/path-to-regexp-0.1.7.tgz
Path to dependency file: /tmp/ws-scm/Notes/Application/package.json
Path to vulnerable library: /tmp/ws-scm/Notes/Application/package.json
Dependency Hierarchy:
Found in base branch: master
Vulnerability Details
path-to-regexp turns path strings into a regular expressions. In certain cases, path-to-regexp will output a regular expression that can be exploited to cause poor performance. The regular expression that is vulnerable to backtracking can be generated in the 0.1.x release of path-to-regexp. Upgrade to 0.1.12. This vulnerability exists because of an incomplete fix for CVE-2024-45296.
Publish Date: 2024-12-05
URL: CVE-2024-52798
CVSS 3 Score Details (7.5)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Origin: GHSA-rhx6-c78j-4q9w
Release Date: 2024-12-05
Fix Resolution (path-to-regexp): 0.1.12
Direct dependency fix Resolution (sails): 1.5.14
Step up your Open Source Security Game with Mend here
Vulnerable Library - body-parser-1.19.2.tgz
Node.js body parsing middleware
Library home page: https://registry.npmjs.org/body-parser/-/body-parser-1.19.2.tgz
Path to dependency file: /tmp/ws-scm/Notes/Application/package.json
Path to vulnerable library: /tmp/ws-scm/Notes/Application/package.json
Dependency Hierarchy:
Found in base branch: master
Vulnerability Details
body-parser is Node.js body parsing middleware. body-parser <1.20.3 is vulnerable to denial of service when url encoding is enabled. A malicious actor using a specially crafted payload could flood the server with a large number of requests, resulting in denial of service. This issue is patched in 1.20.3.
Publish Date: 2024-09-10
URL: CVE-2024-45590
CVSS 3 Score Details (7.5)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Origin: GHSA-qwcr-r2fm-qrc7
Release Date: 2024-09-10
Fix Resolution: body-parser - 1.20.3
Step up your Open Source Security Game with Mend here
Vulnerable Libraries - path-to-regexp-0.1.7.tgz, path-to-regexp-1.5.3.tgz
path-to-regexp-0.1.7.tgz
Express style path to RegExp utility
Library home page: https://registry.npmjs.org/path-to-regexp/-/path-to-regexp-0.1.7.tgz
Path to dependency file: /tmp/ws-scm/Notes/Application/package.json
Path to vulnerable library: /tmp/ws-scm/Notes/Application/package.json
Dependency Hierarchy:
path-to-regexp-1.5.3.tgz
Express style path to RegExp utility
Library home page: https://registry.npmjs.org/path-to-regexp/-/path-to-regexp-1.5.3.tgz
Path to dependency file: /tmp/ws-scm/Notes/Application/package.json
Path to vulnerable library: /tmp/ws-scm/Notes/Application/package.json
Dependency Hierarchy:
Found in base branch: master
Vulnerability Details
path-to-regexp turns path strings into a regular expressions. In certain cases, path-to-regexp will output a regular expression that can be exploited to cause poor performance. Because JavaScript is single threaded and regex matching runs on the main thread, poor performance will block the event loop and lead to a DoS. The bad regular expression is generated any time you have two parameters within a single segment, separated by something that is not a period (.). For users of 0.1, upgrade to 0.1.10. All other users should upgrade to 8.0.0.
Publish Date: 2024-09-09
URL: CVE-2024-45296
CVSS 3 Score Details (7.5)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Origin: GHSA-9wv6-86v2-598j
Release Date: 2024-09-09
Fix Resolution (path-to-regexp): 0.1.10
Direct dependency fix Resolution (sails): 1.5.14
Fix Resolution (path-to-regexp): 0.1.10
Direct dependency fix Resolution (sails): 1.5.14
Step up your Open Source Security Game with Mend here
Vulnerable Library - cross-spawn-4.0.2.tgz
Cross platform child_process#spawn and child_process#spawnSync
Library home page: https://registry.npmjs.org/cross-spawn/-/cross-spawn-4.0.2.tgz
Path to dependency file: /tmp/ws-scm/Notes/Application/package.json
Path to vulnerable library: /tmp/ws-scm/Notes/Application/package.json
Dependency Hierarchy:
Found in base branch: master
Vulnerability Details
Versions of the package cross-spawn before 7.0.5 are vulnerable to Regular Expression Denial of Service (ReDoS) due to improper input sanitization. An attacker can increase the CPU usage and crash the program by crafting a very large and well crafted string.
Publish Date: 2024-11-08
URL: CVE-2024-21538
CVSS 3 Score Details (7.5)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Origin: https://www.cve.org/CVERecord?id=CVE-2024-21538
Release Date: 2024-11-08
Fix Resolution: cross-spawn - 7.0.5
Step up your Open Source Security Game with Mend here
Vulnerable Library - sails-1.5.6.tgz
Library home page: https://registry.npmjs.org/sails/-/sails-1.5.6.tgz
Path to dependency file: /tmp/ws-scm/Notes/Application/package.json
Path to vulnerable library: /tmp/ws-scm/Notes/Application/package.json
Dependency Hierarchy:
Found in base branch: master
Vulnerability Details
Sails is a realtime MVC Framework for Node.js. In Sails apps prior to version 1.5.7,, an attacker can send a virtual request that will cause the node process to crash. This behavior was fixed in Sails v1.5.7. As a workaround, disable the sockets hook and remove the
sails.io.js
client.Publish Date: 2023-07-27
URL: CVE-2023-38504
CVSS 3 Score Details (7.5)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Origin: GHSA-gpw9-fwm8-7rx7
Release Date: 2023-07-27
Fix Resolution: 1.5.7
Step up your Open Source Security Game with Mend here
Vulnerable Library - express-4.17.3.tgz
Fast, unopinionated, minimalist web framework
Library home page: https://registry.npmjs.org/express/-/express-4.17.3.tgz
Path to dependency file: /tmp/ws-scm/Notes/Application/package.json
Path to vulnerable library: /tmp/ws-scm/Notes/Application/package.json
Dependency Hierarchy:
Found in base branch: master
Vulnerability Details
Express.js minimalist web framework for node. Versions of Express.js prior to 4.19.0 and all pre-release alpha and beta versions of 5.0 are affected by an open redirect vulnerability using malformed URLs. When a user of Express performs a redirect using a user-provided URL Express performs an encode using
encodeurl
on the contents before passing it to thelocation
header. This can cause malformed URLs to be evaluated in unexpected ways by common redirect allow list implementations in Express applications, leading to an Open Redirect via bypass of a properly implemented allow list. The main method impacted isres.location()
but this is also called from withinres.redirect()
. The vulnerability is fixed in 4.19.2 and 5.0.0-beta.3.Publish Date: 2024-03-25
URL: CVE-2024-29041
CVSS 3 Score Details (6.1)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Origin: GHSA-rv95-896h-c2vc
Release Date: 2024-03-25
Fix Resolution (express): 4.19.0
Direct dependency fix Resolution (sails): 1.5.10
Step up your Open Source Security Game with Mend here
Vulnerable Libraries - cookie-0.4.0.tgz, cookie-0.3.1.tgz, cookie-0.4.2.tgz
cookie-0.4.0.tgz
HTTP server cookie parsing and serialization
Library home page: https://registry.npmjs.org/cookie/-/cookie-0.4.0.tgz
Path to dependency file: /tmp/ws-scm/Notes/Application/package.json
Path to vulnerable library: /tmp/ws-scm/Notes/Application/package.json
Dependency Hierarchy:
cookie-0.3.1.tgz
HTTP server cookie parsing and serialization
Library home page: https://registry.npmjs.org/cookie/-/cookie-0.3.1.tgz
Path to dependency file: /tmp/ws-scm/Notes/Application/package.json
Path to vulnerable library: /tmp/ws-scm/Notes/Application/package.json
Dependency Hierarchy:
cookie-0.4.2.tgz
HTTP server cookie parsing and serialization
Library home page: https://registry.npmjs.org/cookie/-/cookie-0.4.2.tgz
Path to dependency file: /tmp/ws-scm/Notes/Application/package.json
Path to vulnerable library: /tmp/ws-scm/Notes/Application/package.json
Dependency Hierarchy:
Found in base branch: master
Vulnerability Details
cookie is a basic HTTP cookie parser and serializer for HTTP servers. The cookie name could be used to set other fields of the cookie, resulting in an unexpected cookie value. A similar escape can be used for path and domain, which could be abused to alter other fields of the cookie. Upgrade to 0.7.0, which updates the validation for name, path, and domain.
Publish Date: 2024-10-04
URL: CVE-2024-47764
CVSS 3 Score Details (5.3)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Origin: GHSA-pxg6-pf52-xh8x
Release Date: 2024-10-04
Fix Resolution (cookie): 1.0.1
Direct dependency fix Resolution (sails): 1.5.14
Fix Resolution (cookie): 1.0.1
Direct dependency fix Resolution (sails): 1.5.14
Fix Resolution (cookie): 1.0.1
Direct dependency fix Resolution (sails): 1.5.14
Step up your Open Source Security Game with Mend here
Vulnerable Libraries - semver-5.4.1.tgz, semver-4.3.6.tgz
semver-5.4.1.tgz
The semantic version parser used by npm.
Library home page: https://registry.npmjs.org/semver/-/semver-5.4.1.tgz
Path to dependency file: /tmp/ws-scm/Notes/Application/package.json
Path to vulnerable library: /tmp/ws-scm/Notes/Application/package.json
Dependency Hierarchy:
semver-4.3.6.tgz
The semantic version parser used by npm.
Library home page: https://registry.npmjs.org/semver/-/semver-4.3.6.tgz
Path to dependency file: /tmp/ws-scm/Notes/Application/package.json
Path to vulnerable library: /tmp/ws-scm/Notes/Application/package.json
Dependency Hierarchy:
Found in base branch: master
Vulnerability Details
Versions of the package semver before 7.5.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the function new Range, when untrusted user data is provided as a range.
Publish Date: 2023-06-21
URL: CVE-2022-25883
CVSS 3 Score Details (5.3)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Origin: GHSA-c2qf-rxjj-qqgw
Release Date: 2023-06-21
Fix Resolution (semver): 5.7.2
Direct dependency fix Resolution (sails): 1.5.7
Fix Resolution (semver): 5.7.2
Direct dependency fix Resolution (sails): 1.5.7
Step up your Open Source Security Game with Mend here
Vulnerable Libraries - serve-static-1.14.2.tgz, serve-static-1.13.1.tgz
serve-static-1.14.2.tgz
Serve static files
Library home page: https://registry.npmjs.org/serve-static/-/serve-static-1.14.2.tgz
Path to dependency file: /tmp/ws-scm/Notes/Application/package.json
Path to vulnerable library: /tmp/ws-scm/Notes/Application/package.json
Dependency Hierarchy:
serve-static-1.13.1.tgz
Serve static files
Library home page: https://registry.npmjs.org/serve-static/-/serve-static-1.13.1.tgz
Path to dependency file: /tmp/ws-scm/Notes/Application/package.json
Path to vulnerable library: /tmp/ws-scm/Notes/Application/package.json
Dependency Hierarchy:
Found in base branch: master
Vulnerability Details
serve-static serves static files. serve-static passes untrusted user input - even after sanitizing it - to redirect() may execute untrusted code. This issue is patched in serve-static 1.16.0.
Publish Date: 2024-09-10
URL: CVE-2024-43800
CVSS 3 Score Details (5.0)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Origin: GHSA-cm22-4g7w-348p
Release Date: 2024-09-10
Fix Resolution: serve-static - 1.16.0,2.1.0
Step up your Open Source Security Game with Mend here
Vulnerable Libraries - send-0.17.2.tgz, send-0.16.1.tgz
send-0.17.2.tgz
Better streaming static file server with Range and conditional-GET support
Library home page: https://registry.npmjs.org/send/-/send-0.17.2.tgz
Path to dependency file: /tmp/ws-scm/Notes/Application/package.json
Path to vulnerable library: /tmp/ws-scm/Notes/Application/package.json
Dependency Hierarchy:
send-0.16.1.tgz
Better streaming static file server with Range and conditional-GET support
Library home page: https://registry.npmjs.org/send/-/send-0.16.1.tgz
Path to dependency file: /tmp/ws-scm/Notes/Application/package.json
Path to vulnerable library: /tmp/ws-scm/Notes/Application/package.json
Dependency Hierarchy:
Found in base branch: master
Vulnerability Details
Send is a library for streaming files from the file system as a http response. Send passes untrusted user input to SendStream.redirect() which executes untrusted code. This issue is patched in send 0.19.0.
Publish Date: 2024-09-10
URL: CVE-2024-43799
CVSS 3 Score Details (5.0)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Origin: GHSA-m6fv-jmcg-4jfg
Release Date: 2024-09-10
Fix Resolution: send - 0.19.0
Step up your Open Source Security Game with Mend here
Vulnerable Library - express-4.17.3.tgz
Fast, unopinionated, minimalist web framework
Library home page: https://registry.npmjs.org/express/-/express-4.17.3.tgz
Path to dependency file: /tmp/ws-scm/Notes/Application/package.json
Path to vulnerable library: /tmp/ws-scm/Notes/Application/package.json
Dependency Hierarchy:
Found in base branch: master
Vulnerability Details
Express.js minimalist web framework for node. In express < 4.20.0, passing untrusted user input - even after sanitizing it - to response.redirect() may execute untrusted code. This issue is patched in express 4.20.0.
Publish Date: 2024-09-10
URL: CVE-2024-43796
CVSS 3 Score Details (5.0)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Origin: GHSA-qw6h-vgh9-j6wx
Release Date: 2024-09-10
Fix Resolution (express): 4.21.2
Direct dependency fix Resolution (sails): 1.5.14
Step up your Open Source Security Game with Mend here
The text was updated successfully, but these errors were encountered: