Open Redirect Affecting fastify-static package, versions <4.2.4
Threat Intelligence
EPSS
0.17% (55th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-JS-FASTIFYSTATIC-1728398
- published 6 Oct 2021
- disclosed 5 Oct 2021
- credit drstrnegth
Introduced: 5 Oct 2021
CVE-2021-22963 Open this link in a new tabHow to fix?
Upgrade fastify-static
to version 4.2.4 or higher.
Overview
fastify-static is a plugin for serving static files as fast as possible.
Affected versions of this package are vulnerable to Open Redirect. It allows remote attackers to redirect Mozilla Firefox users to arbitrary websites via a double slash //
followed by a domain - http://localhost:3000//google.com/%2e%2e
.
The issue shows up on all the fastify-static
applications that set the redirect: true
option, which is false
by default.
References
CVSS Scores
version 3.1