Aller au contenu

Fiche vulnérabilité

CVE-2021-21322 : faille critique fastify-http-proxy project… (CVSS 9.8)

Description

fastify-http-proxy is an npm package which is a fastify plugin for proxying your http requests to another server, with hooks. By crafting a specific URL, it is possible to escape the prefix of the proxied backend service. If the base url of the proxied server is `/pub/`, a user expect that accessing `/priv` on the target service would not be possible. In affected versions, it is possible. This is fixed in version 4.3.1.

En bref

Sévérité
Critique (CVSS 9.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
2 mars 2021
Dernière mise à jour
17 juin 2026

Produits concernés

  • fastify-http-proxy project fastify-http-proxy

Références

Rechercher une autre vulnérabilité dans la base CVE