« Volver al listado

CVE-2024-43796

Estado: AnalizadaMedia (4.7)—

Express.js minimalist web framework for node. In express < 4.20.0, passing untrusted user input - even after sanitizing it - to response.redirect() may execute untrusted code. This issue is patched in express 4.20.0.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-43796",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-43796",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-09-10T15:58:36.256748Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-advisories@github.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "HIGH",
          "availabilityImpact": "LOW",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 3.4,
        "exploitabilityScore": 1.6
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 4.7,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 1.6
      }
    ]
  },
  "affected": [
    {
      "source": "security-advisories@github.com",
      "affectedData": [
        {
          "vendor": "expressjs",
          "product": "express",
          "versions": [
            {
              "status": "affected",
              "version": "< 4.20.0"
            },
            {
              "status": "affected",
              "version": ">= 5.0.0-alpha.1, < 5.0.0"
            }
          ]
        }
      ]
    }
  ],
  "published": "2024-09-10T15:15:17.510",
  "references": [
    {
      "url": "https://github.com/expressjs/express/commit/54271f69b511fea198471e6ff3400ab805d6b553",
      "tags": [
        "Patch"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/expressjs/express/security/advisories/GHSA-qw6h-vgh9-j6wx",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security-advisories@github.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security-advisories@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-79"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Express.js minimalist web framework for node. In express < 4.20.0, passing untrusted user input - even after sanitizing it - to response.redirect() may execute untrusted code. This issue is patched in express 4.20.0."
    },
    {
      "lang": "es",
      "value": "Express.js, el framework web minimalista para Node. En Express anterior a la versión 4.20.0, pasar una entrada de usuario no confiable (incluso después de desinfectarla) a response.redirect() puede ejecutar código no confiable. Este problema se solucionó en Express 4.20.0."
    }
  ],
  "lastModified": "2026-06-17T07:51:43.847",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:openjsf:express:*:*:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "490126A5-34FA-4D46-946F-8612A3E66AB1",
              "versionEndExcluding": "4.20.0"
            },
            {
              "criteria": "cpe:2.3:a:openjsf:express:5.0.0:alpha1:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "50C7D4CD-B4D9-433E-B3FC-AB309FA31CCA"
            },
            {
              "criteria": "cpe:2.3:a:openjsf:express:5.0.0:alpha2:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7DFB65DE-73BB-4BB5-84BA-67B187DD2DA9"
            },
            {
              "criteria": "cpe:2.3:a:openjsf:express:5.0.0:alpha3:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B709D2E7-2D50-4A90-B000-0DEB55B80682"
            },
            {
              "criteria": "cpe:2.3:a:openjsf:express:5.0.0:alpha4:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E388EA8E-03EF-41C9-98C6-68D96DAF92A8"
            },
            {
              "criteria": "cpe:2.3:a:openjsf:express:5.0.0:alpha5:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A7D7FA44-E213-4931-A92B-2C46CA1F6EC5"
            },
            {
              "criteria": "cpe:2.3:a:openjsf:express:5.0.0:alpha6:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EBFE2596-A7DE-455C-A59A-1B56ACA82D4F"
            },
            {
              "criteria": "cpe:2.3:a:openjsf:express:5.0.0:alpha7:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F68E52F1-1A06-45D4-8593-3D5D7EC32330"
            },
            {
              "criteria": "cpe:2.3:a:openjsf:express:5.0.0:alpha8:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0F5FEAD7-A1EB-4FB1-8B15-A717642961F0"
            },
            {
              "criteria": "cpe:2.3:a:openjsf:express:5.0.0:beta1:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2CC3B849-8DAF-47E5-A4EB-E93394C7396A"
            },
            {
              "criteria": "cpe:2.3:a:openjsf:express:5.0.0:beta2:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6058D4DD-DE9D-4AD9-87A0-22F81C33F81E"
            },
            {
              "criteria": "cpe:2.3:a:openjsf:express:5.0.0:beta3:*:*:*:node.js:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9852C6CE-F282-4B7D-9690-57E57FAC8B37"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security-advisories@github.com"
}