Aller au contenu

Fiche vulnérabilité

CVE-2024-21536 : faille élevée http-proxy-middleware (CVSS 7.5)

Description

Versions of the package http-proxy-middleware before 2.0.7, from 3.0.0 and before 3.0.3 are vulnerable to Denial of Service (DoS) due to an UnhandledPromiseRejection error thrown by micromatch. An attacker could kill the Node.js process and crash the server by making requests to certain paths.

En bref

Sévérité
Élevée (CVSS 7.5)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P
Exploitation active
Non signalée par la CISA
Publication
19 oct. 2024
Dernière mise à jour
2 août 2026

Produits concernés

  • http-proxy-middleware
  • org.webjars.npm:http-proxy-middleware

Références

Rechercher une autre vulnérabilité dans la base CVE