fastify-http-proxy@4.0.0 vulnerabilities

`fastify-http-proxy@6.3.0` has been deprecated. Please use `@fastify/http-proxy@7.0.0` instead.

  • latest version

    6.3.0

  • latest non vulnerable version

  • first published

    6 years ago

  • latest version published

    2 years ago

  • deprecated

    Package is deprecated

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the fastify-http-proxy package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • H
    Improper Input Validation

    fastify-http-proxy is a proxy http requests, for Fastify

    Affected versions of this package are vulnerable to Improper Input Validation. It is possible to escape the prefix of the proxied backend service by a specially crafted URL. For instance, where the base url of the proxied server is /pub/, a user could gain access to /priv on the target service.

    How to fix Improper Input Validation?

    Upgrade fastify-http-proxy to version 4.3.1 or higher.

    <4.3.1