Description

Hono is a Web application framework that provides support for any JavaScript runtime. Hono CSRF middleware can be bypassed using crafted Content-Type header. MIME types are case insensitive, but isRequestedByFormElementRe only matches lower-case. As a result, attacker can bypass csrf middleware using upper-case form-like MIME type. This vulnerability is fixed in 4.5.8.

INFO

Published Date :

2024-08-22T14:23:44.025Z

Last Modified :

2024-08-22T15:40:32.051Z

Source :

GitHub_M
AFFECTED PRODUCTS

The following products are affected by CVE-2024-43787 vulnerability.

Vendors Products
Eclipse
  • Hono
Hono
  • Hono

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact