CVE-2014-6393
Summary
| CVE | CVE-2014-6393 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-08-09 18:29:00 UTC |
| Updated | 2021-07-30 16:36:00 UTC |
| Description | The Express web framework before 3.11 and 4.x before 4.5 for Node.js does not provide a charset field in HTTP Content-Type headers in 400 level responses, which might allow remote attackers to conduct cross-site scripting (XSS) attacks via characters in a non-standard encoding. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Expressjs | Express | 4.0.0 | All | All | All |
| Application | Expressjs | Express | 4.1.0 | All | All | All |
| Application | Expressjs | Express | 4.1.1 | All | All | All |
| Application | Expressjs | Express | 4.1.2 | All | All | All |
| Application | Expressjs | Express | 4.2.0 | All | All | All |
| Application | Expressjs | Express | 4.3.0 | All | All | All |
| Application | Expressjs | Express | 4.3.1 | All | All | All |
| Application | Expressjs | Express | 4.3.2 | All | All | All |
| Application | Expressjs | Express | 4.4.0 | All | All | All |
| Application | Expressjs | Express | 4.4.1 | All | All | All |
| Application | Expressjs | Express | 4.4.2 | All | All | All |
| Application | Expressjs | Express | 4.4.3 | All | All | All |
| Application | Expressjs | Express | 4.4.4 | All | All | All |
| Application | Expressjs | Express | 4.4.5 | All | All | All |
| Application | Expressjs | Express | 4.0.0 | All | All | All |
| Application | Expressjs | Express | 4.1.0 | All | All | All |
| Application | Expressjs | Express | 4.1.1 | All | All | All |
| Application | Expressjs | Express | 4.1.2 | All | All | All |
| Application | Expressjs | Express | 4.2.0 | All | All | All |
| Application | Expressjs | Express | 4.3.0 | All | All | All |
| Application | Expressjs | Express | 4.3.1 | All | All | All |
| Application | Expressjs | Express | 4.3.2 | All | All | All |
| Application | Expressjs | Express | 4.4.0 | All | All | All |
| Application | Expressjs | Express | 4.4.1 | All | All | All |
| Application | Expressjs | Express | 4.4.2 | All | All | All |
| Application | Expressjs | Express | 4.4.3 | All | All | All |
| Application | Expressjs | Express | 4.4.4 | All | All | All |
| Application | Expressjs | Express | 4.4.5 | All | All | All |
| Application | Expressjs | Express | All | All | All | All |
| Application | Openjsf | Express | 4.0.0 | All | All | All |
| Application | Openjsf | Express | 4.1.0 | All | All | All |
| Application | Openjsf | Express | 4.1.1 | All | All | All |
| Application | Openjsf | Express | 4.1.2 | All | All | All |
| Application | Openjsf | Express | 4.2.0 | All | All | All |
| Application | Openjsf | Express | 4.3.0 | All | All | All |
| Application | Openjsf | Express | 4.3.1 | All | All | All |
| Application | Openjsf | Express | 4.3.2 | All | All | All |
| Application | Openjsf | Express | 4.4.0 | All | All | All |
| Application | Openjsf | Express | 4.4.1 | All | All | All |
| Application | Openjsf | Express | 4.4.2 | All | All | All |
| Application | Openjsf | Express | 4.4.3 | All | All | All |
| Application | Openjsf | Express | 4.4.4 | All | All | All |
| Application | Openjsf | Express | 4.4.5 | All | All | All |
| Application | Openjsf | Express | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 1203190 – (CVE-2014-6393) CVE-2014-6393 express: cross-site scripting via content-type header | CONFIRM | bugzilla.redhat.com | Issue Tracking, Third Party Advisory, VDB Entry |
| Node Security Project | express No Charset in Content-Type Header | CONFIRM | nodesecurity.io | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 981815 Nodejs (npm) Security Update for express (GHSA-gpvr-g6gh-9mc2)