CVE-2024-43800
10.09.2024, 15:15
serve-static serves static files. serve-static passes untrusted user input - even after sanitizing it - to redirect() may execute untrusted code. This issue is patched in serve-static 1.16.0.
| Vendor | Product | Version |
|---|---|---|
| openjsf | serve-static | 𝑥 < 1.16.0 |
| openjsf | serve-static | 2.0.0 ≤ 𝑥 < 2.1.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases