fastify-reply-from is an npm package which is a fastify plugin to forward the current http request to another server. In fastify-reply-from before version 4.0.2, by crafting a specific URL, it is possible to escape the prefix of the proxied backend service. If the base url of the proxied server is "/pub/", a user expect that accessing "/priv" on the target service would not be possible. In affected versions, it is possible. This is fixed in version 4.0.2.
History

Sun, 08 Sep 2024 18:30:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:acm:2.2::el7

Mon, 19 Aug 2024 22:15:00 +0000

Type Values Removed Values Added
CPEs cpe:/a:redhat:acm:2.2::el7
cpe:/a:redhat:acm:2.2::el8

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2021-03-02T03:35:25

Updated: 2024-08-03T18:09:15.260Z

Reserved: 2020-12-22T00:00:00

Link: CVE-2021-21321

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2021-03-02T04:15:12.487

Modified: 2021-03-09T13:43:17.273

Link: CVE-2021-21321

cve-icon Redhat

Severity : Critical

Publid Date: 2021-02-23T00:00:00Z

Links: CVE-2021-21321 - Bugzilla