6.1

CVE-2025-8129

Exploit
A vulnerability, which was classified as problematic, was found in KoaJS Koa up to 3.0.0. Affected is the function back in the library lib/response.js of the component HTTP Header Handler. The manipulation of the argument Referrer leads to open redirect. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
KoajsKoa SwPlatformnode.js Version >= 2.0.0 < 2.16.2
KoajsKoa Version3.0.0 Update- SwPlatformnode.js
KoajsKoa Version3.0.0 Updatealpha0 SwPlatformnode.js
KoajsKoa Version3.0.0 Updatealpha1 SwPlatformnode.js
KoajsKoa Version3.0.0 Updatealpha2 SwPlatformnode.js
KoajsKoa Version3.0.0 Updatealpha3 SwPlatformnode.js
KoajsKoa Version3.0.0 Updatealpha4 SwPlatformnode.js
KoajsKoa Version3.0.0 Updatealpha5 SwPlatformnode.js
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.05% 0.169
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.1 2.8 2.7
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
cna@vuldb.com 5.1 0 0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
cna@vuldb.com 3.5 2.1 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
cna@vuldb.com 4 8 2.9
AV:N/AC:L/Au:S/C:N/I:P/A:N
CWE-601 URL Redirection to Untrusted Site ('Open Redirect')

The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.

https://github.com/koajs/koa/issues/1892
Patch
Vendor Advisory
Exploit
Issue Tracking
https://github.com/koajs/koa/issues/1892#issue-3213028583
Patch
Third Party Advisory
Vendor Advisory
Exploit
Issue Tracking
https://vuldb.com/?ctiid.317514
VDB Entry
Permissions Required
https://vuldb.com/?id.317514
Third Party Advisory
VDB Entry
https://vuldb.com/?submit.619741
Third Party Advisory
VDB Entry