Versions of the package @nestjs/core before 9.0.5 are vulnerable to Information Exposure via the StreamableFile pipe. Exploiting this vulnerability is possible when the client cancels a request while it is streaming a StreamableFile, the stream wrapped by the StreamableFile will be kept open.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 05 Mar 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: snyk

Published:

Updated: 2025-03-05T19:48:14.569Z

Reserved: 2023-02-20T10:28:48.922Z

Link: CVE-2023-26108

cve-icon Vulnrichment

Updated: 2024-08-02T11:39:06.621Z

cve-icon NVD

Status : Modified

Published: 2023-03-06T05:15:12.690

Modified: 2024-11-21T07:50:47.483

Link: CVE-2023-26108

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.