REDHAT-BUG-2444584: High severity npm/multer vulnerability
Multer is a node.js middleware for handling multipart/form-data. A vulnerability in Multer prior to version 2.1.1 allows an attacker to trigger a Denial of Service (DoS) by sending malformed requests, potentially causing stack overflow. Users should upgrade to version 2.1.1 to receive a patch. No known workarounds are available.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
multerto a version that resolves this vulnerability.Fixed in 2.1.1
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2444584?
The severity of REDHAT-BUG-2444584 is high, rated at 7.
How do I fix REDHAT-BUG-2444584?
To resolve REDHAT-BUG-2444584, users should upgrade Multer to version 2.1.1 or later.
What type of vulnerability is REDHAT-BUG-2444584?
REDHAT-BUG-2444584 is a Denial of Service (DoS) vulnerability affecting Multer.
What can an attacker achieve with the REDHAT-BUG-2444584 vulnerability?
An attacker can cause a Denial of Service by sending malformed requests, potentially leading to a stack overflow.
Who is affected by REDHAT-BUG-2444584?
Users of Multer prior to version 2.1.1 are affected by REDHAT-BUG-2444584.