This affects the package express-fileupload before 1.1.8. If the parseNested option is enabled, sending a corrupt HTTP request can lead to denial of service or arbitrary code execution.
2020-07-30T09:15:11.373
2024-11-21T05:37:38.190
Modified
CVSSv3.1: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:P/I:P/A:P
10.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | express-fileupload_project | express-fileupload | < 1.1.8 | Yes |
Application | netapp | max_data | - | Yes |