serve-static serves static files. serve-static passes untrusted user input - even after sanitizing it - to redirect() may execute untrusted code. This issue is patched in serve-static 1.16.0.
2024-09-10T15:15:17.937
2024-09-20T17:36:30.313
Analyzed
CVSSv3.1: 5.0 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | openjsf | serve-static | < 1.16.0 | Yes |
Application | openjsf | serve-static | < 2.1.0 | Yes |