CVE-2024-21536
גבוהה 7.5
תיאור (מקור, אנגלית)
Versions of the package http-proxy-middleware before 2.0.7, from 3.0.0 and before 3.0.3 are vulnerable to Denial of Service (DoS) due to an UnhandledPromiseRejection error thrown by micromatch. An attacker could kill the Node.js process and crash the server by making requests to certain paths.
מדדים
- CVSS 3.1
-
7.5 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H - CVSS 4.0
-
7.7 (HIGH)
מקור הציון: CNA
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X - EPSS — סבירות ניצול
- 1% (אחוזון 100) נכון ל-19/9/2026
- CWE
- CWE-400
מוצרים מושפעים
chimurai: http-proxy-middleware
קישורים
- https://github.com/chimurai/http-proxy-middleware/commit/0b4274e8cc9e9a2c5a06f… Patch
- https://github.com/chimurai/http-proxy-middleware/commit/788b21e4aff38332d6319… Patch
- https://gist.github.com/mhassan1/28be67266d82a53708ed59ce5dc3c94a ExploitThird Party Advisory
- https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-8309098
- https://security.snyk.io/vuln/SNYK-JS-HTTPPROXYMIDDLEWARE-8229906 Third Party Advisory