REDHAT-BUG-2443367: High severity npm/@nestjs/platform-fastify vulnerability
A NestJS application using @nestjs/platform-fastify can allow bypass of authentication/authorization middleware when Fastify path-normalization options are enabled.
This issue affects nest.Js: 11.1.13.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
nest.Jsto a version that resolves this vulnerability.Fixed in 11.1.13
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2443367?
The severity of REDHAT-BUG-2443367 is classified as high with a rating of 7.
How do I fix REDHAT-BUG-2443367?
To mitigate REDHAT-BUG-2443367, ensure you update your NestJS application to a version higher than 11.1.13 and disable Fastify path-normalization options.
What is the impact of REDHAT-BUG-2443367?
REDHAT-BUG-2443367 allows attackers to bypass authentication and authorization middleware in NestJS applications.
Which versions of NestJS are affected by REDHAT-BUG-2443367?
REDHAT-BUG-2443367 affects NestJS version 11.1.13 when using the @nestjs/platform-fastify package.
What features are exploited in REDHAT-BUG-2443367?
REDHAT-BUG-2443367 exploits Fastify path-normalization options to bypass authentication/authorization middleware.