VDB
Sign up
MEDIUM

GHSA-2q7r-29rg-6m5h

fastify-reply-from affected by bypass of reply forwarding

Quick fix

GHSA-2q7r-29rg-6m5h — @fastify/reply-from: upgrade to the fixed version with the command below.

npm install @fastify/reply-from@12.5.0

Details

### Summary By crafting a malicious URL, an attacker could access routes that are not allowed, even though the `reply.from` is defined for specific routes in `@fastify/reply-from`.

### Details

An attacker can bypass the route defined by the `@fastify/reply-from` package by adding a `..` symbol, which, for `curl` version `8.7.1`, is `%2e%2e`.

### Impact

Everyone is using this package with the routes option to protect a 3rd-party resource.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@fastify/reply-from
Introduced in: 0Fixed in: 12.5.0
Fixnpm install @fastify/reply-from@12.5.0

References