Description

Versions of the package http-proxy-middleware before 2.0.7, from 3.0.0 and before 3.0.3 are vulnerable to Denial of Service (DoS) due to an UnhandledPromiseRejection error thrown by micromatch. An attacker could kill the Node.js process and crash the server by making requests to certain paths.

INFO

Published Date :

2024-10-19T05:00:04.056Z

Last Modified :

2024-10-21T16:31:29.125Z

Source :

snyk
AFFECTED PRODUCTS

The following products are affected by CVE-2024-21536 vulnerability.

Vendors Products
Chimurai
  • Http-proxy-middleware
Redhat
  • Advanced Cluster Security
  • Discovery
  • Openshift Data Foundation
  • Openshift Distributed Tracing
  • Rhdh
  • Rhmt
  • Service Mesh
  • Trusted Profile Analyzer

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact