VDB
Sign up
CRITICAL9.1

GHSA-8m85-wqg7-c529

SAP Approuter Vulnerable to HTTP Request Smuggling

Quick fix

GHSA-8m85-wqg7-c529 — @sap/approuter: upgrade to the fixed version with the command below.

npm install @sap/approuter@20.10.0

Details

Due to an HTTP Request Smuggling vulnerability in SAP Approuter, an unauthenticated attacker could send a specially crafted HTTP request that leads to request-response desynchronization. This could result in the exposure of user responses and cause the system to become unavailable. This leads to a high impact on confidentiality and availability.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@sap/approuter
Introduced in: 0Fixed in: 20.10.0
Fixnpm install @sap/approuter@20.10.0

References