QID 981860
QID 981860: Nodejs (npm) Security Update for express-fileupload (GHSA-9wcg-jrwf-8gg7)
This affects the package express-fileupload before 1.1.8. If the parseNested option is enabled, sending a corrupt HTTP request can lead to denial of service or arbitrary code execution.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-9wcg-jrwf-8gg7 for updates pertaining to this vulnerability.
Vendor References
- GHSA-9wcg-jrwf-8gg7 -
github.com/advisories/GHSA-9wcg-jrwf-8gg7
CVEs related to QID 981860
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-9wcg-jrwf-8gg7 | express-fileupload |
|