First published: Tue Sep 10 2024(Updated: )
body-parser is Node.js body parsing middleware. body-parser <1.20.3 is vulnerable to denial of service when url encoding is enabled. A malicious actor using a specially crafted payload could flood the server with a large number of requests, resulting in denial of service. This issue is patched in 1.20.3.
Affected Software | Affected Version | How to fix |
---|---|---|
body-parser | <1.20.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of REDHAT-BUG-2311171 is classified as high due to its potential to cause denial of service.
To fix REDHAT-BUG-2311171, upgrade the body-parser package to version 1.20.3 or later.
Applications using body-parser versions prior to 1.20.3 that enable URL encoding are affected by REDHAT-BUG-2311171.
REDHAT-BUG-2311171 is a denial of service vulnerability.
Yes, REDHAT-BUG-2311171 can be remotely exploited if a malicious actor sends specially crafted payloads.