CVE-2022-23623
Summary
| CVE | CVE-2022-23623 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-02-07 23:15:00 UTC |
| Updated | 2023-07-13 15:52:00 UTC |
| Description | Frourio is a full stack framework, for TypeScript. Frourio users who uses frourio version prior to v0.26.0 and integration with class-validator through `validators/` folder are subject to a input validation vulnerability. Validators do not work properly for request bodies and queries in specific situations and some input is not validated at all. Users are advised to update frourio to v0.26.0 or later and to install `class-transformer` and `reflect-metadata`. |
Risk And Classification
Problem Types: CWE-20 | CWE-1321
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| feat(validation): use class-transformer to support validation of nest… · frouriojs/frourio@7c19ac5 · GitHub | MISC | github.com | |
| Class validators defined by users with frourio does not work properly for specific cases. · Advisory · frouriojs/frourio · GitHub | CONFIRM | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.