5

CVE-2024-43796

Express.js minimalist web framework for node. In express < 4.20.0, passing untrusted user input - even after sanitizing it - to response.redirect() may execute untrusted code. This issue is patched in express 4.20.0.

Data is provided by the National Vulnerability Database (NVD)
OpenjsfExpress SwPlatformnode.js Version < 4.20.0
OpenjsfExpress Version5.0.0 Updatealpha1 SwPlatformnode.js
OpenjsfExpress Version5.0.0 Updatealpha2 SwPlatformnode.js
OpenjsfExpress Version5.0.0 Updatealpha3 SwPlatformnode.js
OpenjsfExpress Version5.0.0 Updatealpha4 SwPlatformnode.js
OpenjsfExpress Version5.0.0 Updatealpha5 SwPlatformnode.js
OpenjsfExpress Version5.0.0 Updatealpha6 SwPlatformnode.js
OpenjsfExpress Version5.0.0 Updatealpha7 SwPlatformnode.js
OpenjsfExpress Version5.0.0 Updatealpha8 SwPlatformnode.js
OpenjsfExpress Version5.0.0 Updatebeta1 SwPlatformnode.js
OpenjsfExpress Version5.0.0 Updatebeta2 SwPlatformnode.js
OpenjsfExpress Version5.0.0 Updatebeta3 SwPlatformnode.js
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.06% 0.18
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.7 1.6 2.7
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N
security-advisories@github.com 5 1.6 3.4
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.