CVE-2024-43800

serve-static serves static files. serve-static passes untrusted user input - even after sanitizing it - to redirect() may execute untrusted code. This issue is patched in serve-static 1.16.0.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:openjsf:serve-static:*:*:*:*:*:node.js:*:*
cpe:2.3:a:openjsf:serve-static:*:*:*:*:*:node.js:*:*

History

No history.

Information

Published : 2024-09-10 15:15

Updated : 2024-09-20 17:36


NVD link : CVE-2024-43800

Mitre link : CVE-2024-43800

CVE.ORG link : CVE-2024-43800


JSON object : View

Products Affected

openjsf

  • serve-static
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')