Versions of the package http-proxy-middleware before 2.0.7, from 3.0.0 and before 3.0.3 are vulnerable to Denial of Service (DoS) due to an UnhandledPromiseRejection error thrown by micromatch. An attacker could kill the Node.js process and crash the server by making requests to certain paths.
History

Tue, 17 Dec 2024 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Redhat trusted Profile Analyzer
CPEs cpe:/a:redhat:trusted_profile_analyzer:1.2::el9
Vendors & Products Redhat trusted Profile Analyzer

Thu, 12 Dec 2024 02:30:00 +0000

Type Values Removed Values Added
First Time appeared Redhat openshift Distributed Tracing
CPEs cpe:/a:redhat:openshift_distributed_tracing:3.4::el8
Vendors & Products Redhat openshift Distributed Tracing

Sat, 16 Nov 2024 02:45:00 +0000

Type Values Removed Values Added
First Time appeared Redhat
Redhat service Mesh
CPEs cpe:/a:redhat:service_mesh:2.6::el8
cpe:/a:redhat:service_mesh:2.6::el9
Vendors & Products Redhat
Redhat service Mesh

Fri, 01 Nov 2024 18:30:00 +0000

Type Values Removed Values Added
Weaknesses NVD-CWE-noinfo

Mon, 21 Oct 2024 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Chimurai
Chimurai http-proxy-middleware
CPEs cpe:2.3:a:chimurai:http-proxy-middleware:*:*:*:*:*:*:*:*
Vendors & Products Chimurai
Chimurai http-proxy-middleware
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 21 Oct 2024 13:30:00 +0000

Type Values Removed Values Added
Title http-proxy-middleware: Denial of Service
References
Metrics threat_severity

None

threat_severity

Moderate


Sat, 19 Oct 2024 05:15:00 +0000

Type Values Removed Values Added
Description Versions of the package http-proxy-middleware before 2.0.7, from 3.0.0 and before 3.0.3 are vulnerable to Denial of Service (DoS) due to an UnhandledPromiseRejection error thrown by micromatch. An attacker could kill the Node.js process and crash the server by making requests to certain paths.
Weaknesses CWE-400
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: snyk

Published: 2024-10-19T05:00:04.056Z

Updated: 2024-10-21T16:31:29.125Z

Reserved: 2023-12-22T12:33:20.123Z

Link: CVE-2024-21536

cve-icon Vulnrichment

Updated: 2024-10-21T15:47:24.380Z

cve-icon NVD

Status : Analyzed

Published: 2024-10-19T05:15:13.097

Modified: 2024-11-01T18:03:15.897

Link: CVE-2024-21536

cve-icon Redhat

Severity : Moderate

Publid Date: 2024-10-19T05:00:04Z

Links: CVE-2024-21536 - Bugzilla