VDB

ANCHORE-2024-43796

ANCHORE-2024-43796 PUBLISHED

Express.js minimalist web framework for node. In express < 4.20.0, passing untrusted user input - even after sanitizing it - to response.redirect() may execute untrusted code. This issue is patched in express 4.20.0.

Affected Products

VendorProductVersions
expressjsexpress0, 5.0.0-alpha.1, 0

Timeline

  • Sep 10, 2024 CVE Published
Open in Interactive Console →
$ Console Community · 100/wk Open console ›