Versions of the package http-proxy-middleware before 2.0.7, from 3.0.0 and before 3.0.3 are vulnerable to Denial of Service (DoS) due to an UnhandledPromiseRejection error thrown by micromatch. An attacker could kill the Node.js process and crash the server by making requests to certain paths.
History

Fri, 01 Nov 2024 18:30:00 +0000

Type Values Removed Values Added
Weaknesses NVD-CWE-noinfo

Mon, 21 Oct 2024 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Chimurai
Chimurai http-proxy-middleware
CPEs cpe:2.3:a:chimurai:http-proxy-middleware:*:*:*:*:*:*:*:*
Vendors & Products Chimurai
Chimurai http-proxy-middleware
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 21 Oct 2024 13:30:00 +0000

Type Values Removed Values Added
Title http-proxy-middleware: Denial of Service
References
Metrics threat_severity

None

threat_severity

Moderate


Sat, 19 Oct 2024 05:15:00 +0000

Type Values Removed Values Added
Description Versions of the package http-proxy-middleware before 2.0.7, from 3.0.0 and before 3.0.3 are vulnerable to Denial of Service (DoS) due to an UnhandledPromiseRejection error thrown by micromatch. An attacker could kill the Node.js process and crash the server by making requests to certain paths.
Weaknesses CWE-400
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: snyk

Published: 2024-10-19T05:00:04.056Z

Updated: 2024-10-21T16:31:29.125Z

Reserved: 2023-12-22T12:33:20.123Z

Link: CVE-2024-21536

cve-icon Vulnrichment

Updated: 2024-10-21T15:47:24.380Z

cve-icon NVD

Status : Analyzed

Published: 2024-10-19T05:15:13.097

Modified: 2024-11-01T18:03:15.897

Link: CVE-2024-21536

cve-icon Redhat

Severity : Moderate

Publid Date: 2024-10-19T05:00:04Z

Links: CVE-2024-21536 - Bugzilla