Podatliwość w KoaJS Koa do wersji 3.0.0 została klasyfikowana jako problematyczna. Dotyczy funkcji back w pliku lib/response.js komponentu HTTP Header Handler. Manipulacja parametrem Referrer prowadzi do open redirect. Atak można przeprowadzić zdalnie, a exploit został ujawniony publicznie.
▸ Pokaż oryginał (EN)
A vulnerability, which was classified as problematic, was found in KoaJS Koa up to 3.0.0. Affected is the function back in the library lib/response.js of the component HTTP Header Handler. The manipulation of the argument Referrer leads to open redirect. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XKoajs Koa
APPKoajs3.0.02.0.0 – 2.16.2 (bez)
Powiązane podatności
Atak DoS przez podatność ReDoS w nagłówkach HTTP w Koa (Node.js)
Koa is middleware for Node.js using ES2017 async functions. Prior to versions 3.1.2 and 2.16.4, Koa's `ctx.hos...
Koa is expressive middleware for Node.js using ES2017 async functions. In versions 2.16.2 to before 2.16.3 and...
Koa is expressive middleware for Node.js using ES2017 async functions. In koa < 2.16.1 and < 3.0.0-alpha.5, pa...
@koa/cors npm provides Cross-Origin Resource Sharing (CORS) for koa, a web framework for Node.js. Prior to ver...