Metrics
Affected Vendors & Products
No reference.
Wed, 03 Dec 2025 09:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | express improperly controls modification of query properties | |
| Metrics |
ssvc
|
Tue, 02 Dec 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | express improperly controls modification of query properties | |
| Metrics |
ssvc
|
Tue, 02 Dec 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | express improperly controls modification of query properties | |
| Metrics |
ssvc
|
Tue, 02 Dec 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-915 | |
| References |
|
|
| Metrics |
cvssV4_0
|
Tue, 02 Dec 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Express.js minimalist web framework for node. Prior to 5.2.0 and 4.22.0, when using the extended query parser in express ('query parser': 'extended'), the request.query object inherits all object prototype properties, but these properties can be overwritten by query string parameter keys that match the property names. This vulnerability is fixed in 5.2.0 and 4.22.0. | ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error and is not a valid vulnerability. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage. |
| Metrics |
cvssV4_0
|
cvssV4_0
|
Tue, 02 Dec 2025 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Expressjs
Expressjs express |
|
| Vendors & Products |
Expressjs
Expressjs express |
Mon, 01 Dec 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 01 Dec 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Express.js minimalist web framework for node. Prior to 5.2.0 and 4.22.0, when using the extended query parser in express ('query parser': 'extended'), the request.query object inherits all object prototype properties, but these properties can be overwritten by query string parameter keys that match the property names. This vulnerability is fixed in 5.2.0 and 4.22.0. | |
| Title | express improperly controls modification of query properties | |
| Weaknesses | CWE-915 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: REJECTED
Assigner: GitHub_M
Published: 2025-12-01T20:17:53.641Z
Updated: 2025-12-02T15:01:15.735Z
Reserved: 2024-11-04T17:46:16.778Z
Link: CVE-2024-51999
Updated:
Status : Rejected
Published: 2025-12-01T21:15:49.100
Modified: 2025-12-02T15:15:48.063
Link: CVE-2024-51999
No data.
ReportizFlow