CVE-2024-43796

Express.js minimalist web framework for node. In express < 4.20.0, passing untrusted user input - even after sanitizing it - to response.redirect() may execute untrusted code. This issue is patched in express 4.20.0.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:openjsf:express:*:*:*:*:*:node.js:*:*
cpe:2.3:a:openjsf:express:5.0.0:alpha1:*:*:*:node.js:*:*
cpe:2.3:a:openjsf:express:5.0.0:alpha2:*:*:*:node.js:*:*
cpe:2.3:a:openjsf:express:5.0.0:alpha3:*:*:*:node.js:*:*
cpe:2.3:a:openjsf:express:5.0.0:alpha4:*:*:*:node.js:*:*
cpe:2.3:a:openjsf:express:5.0.0:alpha5:*:*:*:node.js:*:*
cpe:2.3:a:openjsf:express:5.0.0:alpha6:*:*:*:node.js:*:*
cpe:2.3:a:openjsf:express:5.0.0:alpha7:*:*:*:node.js:*:*
cpe:2.3:a:openjsf:express:5.0.0:alpha8:*:*:*:node.js:*:*
cpe:2.3:a:openjsf:express:5.0.0:beta1:*:*:*:node.js:*:*
cpe:2.3:a:openjsf:express:5.0.0:beta2:*:*:*:node.js:*:*
cpe:2.3:a:openjsf:express:5.0.0:beta3:*:*:*:node.js:*:*

History

No history.

Information

Published : 2024-09-10 15:15

Updated : 2024-09-20 16:07


NVD link : CVE-2024-43796

Mitre link : CVE-2024-43796

CVE.ORG link : CVE-2024-43796


JSON object : View

Products Affected

openjsf

  • express
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')