6.1

CVE-2025-8129

Exploit

KoaJS Koa HTTP Header response.js back redirect

A vulnerability, which was classified as problematic, was found in KoaJS Koa up to 3.0.0. Affected is the function back in the library lib/response.js of the component HTTP Header Handler. The manipulation of the argument Referrer leads to open redirect. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Koajs ≫ Koa SwPlatform node.js Version >= 2.0.0 < 2.16.2
Koajs ≫ Koa Version 3.0.0 Update - SwPlatform node.js
Koajs ≫ Koa Version 3.0.0 Update alpha0 SwPlatform node.js
Koajs ≫ Koa Version 3.0.0 Update alpha1 SwPlatform node.js
Koajs ≫ Koa Version 3.0.0 Update alpha2 SwPlatform node.js
Koajs ≫ Koa Version 3.0.0 Update alpha3 SwPlatform node.js
Koajs ≫ Koa Version 3.0.0 Update alpha4 SwPlatform node.js
Koajs ≫ Koa Version 3.0.0 Update alpha5 SwPlatform node.js
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.23% 0.143
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.1 2.8 2.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
cna@vuldb.com 2 0 0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
cna@vuldb.com 3.5 2.1 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
cna@vuldb.com 4 8 2.9
AV:N/AC:L/Au:S/C:N/I:P/A:N
CWE-601 URL Redirection to Untrusted Site ('Open Redirect')

The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.

https://github.com/koajs/koa/issues/1892
Patch
Vendor Advisory
Exploit
Issue Tracking
https://github.com/koajs/koa/issues/1892#issue-3213028583
Patch
Third Party Advisory
Vendor Advisory
Exploit
Issue Tracking
https://vuldb.com/?ctiid.317514
VDB Entry
Permissions Required
https://vuldb.com/?id.317514
Third Party Advisory
VDB Entry
https://vuldb.com/?submit.619741
Third Party Advisory
VDB Entry