CRITICAL9.8
GHSA-9wcg-jrwf-8gg7
Prototype Pollution in express-fileupload
Quick fix
GHSA-9wcg-jrwf-8gg7 — express-fileupload: upgrade to the fixed version with the command below.
npm install express-fileupload@1.1.9Details
This affects the package express-fileupload before 1.1.8. If the parseNested option is enabled, sending a corrupt HTTP request can lead to denial of service or arbitrary code execution.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2020-7699[ADVISORY]
- https://github.com/richardgirges/express-fileupload/issues/236[WEB]
- https://github.com/richardgirges/express-fileupload/pull/237[WEB]
- https://github.com/richardgirges/express-fileupload/commit/db495357d7557ceb5c034de91a7a574bd12f9b9f[WEB]
- https://github.com/richardgirges/express-fileupload[PACKAGE]
- https://security.netapp.com/advisory/ntap-20200821-0003[WEB]
- https://snyk.io/vuln/SNYK-JS-EXPRESSFILEUPLOAD-595969[WEB]