First published: Tue Sep 10 2024(Updated: )
Express.js minimalist web framework for node. In express < 4.20.0, passing untrusted user input - even after sanitizing it - to response.redirect() may execute untrusted code. This issue is patched in express 4.20.0.
Affected Software | Affected Version | How to fix |
---|---|---|
EXPRESS EXPRESS | <4.20.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-2311152 is classified as critical due to the risk of executing untrusted code when using response.redirect().
To fix REDHAT-BUG-2311152, upgrade Express.js to version 4.20.0 or higher.
Not resolving REDHAT-BUG-2311152 may allow attackers to execute arbitrary code through manipulated user input.
Express.js versions before 4.20.0 are affected by REDHAT-BUG-2311152.
Yes, a patch for REDHAT-BUG-2311152 is available in Express.js version 4.20.0.