REDHAT-BUG-2443350: High severity npm/multer vulnerability
Multer is a node.js middleware for handling multipart/form-data. A vulnerability in Multer prior to version 2.1.0 allows an attacker to trigger a Denial of Service (DoS) by dropping connection during file upload, potentially causing resource exhaustion. Users should upgrade to version 2.1.0 to receive a patch. No known workarounds are available.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
multerto a version that resolves this vulnerability.Fixed in 2.1.0
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2443350?
The severity of REDHAT-BUG-2443350 is classified as high with a score of 7.
What is the impact of REDHAT-BUG-2443350?
The impact of REDHAT-BUG-2443350 is a potential Denial of Service (DoS) attack that may cause resource exhaustion.
How do I fix REDHAT-BUG-2443350?
To fix REDHAT-BUG-2443350, upgrade Multer to version 2.1.0 or later.
Which software is affected by REDHAT-BUG-2443350?
The affected software for REDHAT-BUG-2443350 is npm/multer.
What versions of Multer are vulnerable in relation to REDHAT-BUG-2443350?
Versions of Multer prior to 2.1.0 are vulnerable in relation to REDHAT-BUG-2443350.