CVE-2024-10491

All FrameworksExpress.jsCWE-74CVE-2024-10491

CVE-2024-10491

State: PUBLISHED · Published: 2024-10-29 · Updated: 2024-10-29 · Assigner: HeroDevs
Description
A vulnerability has been identified in the Express response.links function, allowing for arbitrary resource injection in the Link header when unsanitized data is used. The issue arises from improper sanitization in `Link` header values, which can allow a combination of characters like `,`, `;`, and `<>` to preload malicious resources. This vulnerability is especially relevant for dynamic parameters.
CWE
Affected
CVSS
References
Source
cvelistV5-main/cves/2024/10xxx/CVE-2024-10491.json