REDHAT-BUG-2443353: High severity npm/multer vulnerability
Multer is a node.js middleware for handling multipart/form-data. A vulnerability in Multer prior to version 2.1.0 allows an attacker to trigger a Denial of Service (DoS) by sending malformed requests, potentially causing resource exhaustion. Users should upgrade to version 2.1.0 to receive a patch. No known workarounds are available.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
multerto a version that resolves this vulnerability.Fixed in 2.1.0
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2443353?
The severity of REDHAT-BUG-2443353 is classified as high with a score of 7.
What vulnerability is identified in REDHAT-BUG-2443353?
REDHAT-BUG-2443353 identifies a Denial of Service (DoS) vulnerability in Multer versions prior to 2.1.0.
How do I fix REDHAT-BUG-2443353?
To fix REDHAT-BUG-2443353, users should upgrade to Multer version 2.1.0 or later.
What type of attack does REDHAT-BUG-2443353 allow?
REDHAT-BUG-2443353 allows an attacker to trigger a Denial of Service (DoS) by sending malformed requests.
What is the impact of the vulnerability in REDHAT-BUG-2443353?
The impact of the vulnerability in REDHAT-BUG-2443353 is potential resource exhaustion leading to Denial of Service.