CVE-2024-21536

EUVD-2024-3014
Versions of the package http-proxy-middleware before 2.0.7, from 3.0.0 and before 3.0.3 are vulnerable to Denial of Service (DoS) due to an UnhandledPromiseRejection error thrown by micromatch. An attacker could kill the Node.js process and crash the server by making requests to certain paths.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 57%
Affected Products (NVD)
VendorProductVersion
chimuraihttp-proxy-middleware
𝑥
< 2.0.7
chimuraihttp-proxy-middleware
3.0.0 ≤
𝑥
< 3.0.3
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
chimuraihttp-proxy-middleware
𝑥
< 2.0.7
ADP
chimuraihttp-proxy-middleware
3.0.0 ≤
𝑥
< 3.0.3
ADP