Versions of the package http-proxy-middleware before 2.0.7, from 3.0.0 and before 3.0.3 are vulnerable to Denial of Service (DoS) due to an UnhandledPromiseRejection error thrown by micromatch. An attacker could kill the Node.js process and crash the server by making requests to certain paths.
Metrics
Affected Vendors & Products
References
History
Fri, 01 Nov 2024 18:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | NVD-CWE-noinfo |
Mon, 21 Oct 2024 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Chimurai
Chimurai http-proxy-middleware |
|
CPEs | cpe:2.3:a:chimurai:http-proxy-middleware:*:*:*:*:*:*:*:* | |
Vendors & Products |
Chimurai
Chimurai http-proxy-middleware |
|
Metrics |
ssvc
|
Mon, 21 Oct 2024 13:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Title | http-proxy-middleware: Denial of Service | |
References |
| |
Metrics |
threat_severity
|
threat_severity
|
Sat, 19 Oct 2024 05:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Versions of the package http-proxy-middleware before 2.0.7, from 3.0.0 and before 3.0.3 are vulnerable to Denial of Service (DoS) due to an UnhandledPromiseRejection error thrown by micromatch. An attacker could kill the Node.js process and crash the server by making requests to certain paths. | |
Weaknesses | CWE-400 | |
References |
|
|
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: snyk
Published: 2024-10-19T05:00:04.056Z
Updated: 2024-10-21T16:31:29.125Z
Reserved: 2023-12-22T12:33:20.123Z
Link: CVE-2024-21536
Vulnrichment
Updated: 2024-10-21T15:47:24.380Z
NVD
Status : Analyzed
Published: 2024-10-19T05:15:13.097
Modified: 2024-11-01T18:03:15.897
Link: CVE-2024-21536
Redhat