Open Redirect Affecting fastify-static package, versions >=4.2.4 <4.4.1
Threat Intelligence
EPSS
0.15% (53rd
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-JS-FASTIFYSTATIC-1730571
- published 13 Oct 2021
- disclosed 12 Oct 2021
- credit Unknown
How to fix?
Upgrade fastify-static
to version 4.4.1 or higher.
Overview
fastify-static is a plugin for serving static files as fast as possible.
Affected versions of this package are vulnerable to Open Redirect via a double slash followed by a domain. This may lead to a Denial-of-Service if the url contains invalid characters such as curl --path-as-is "http://localhost:3000//^/.."
.
Note:
This only applies to Mozilla Firefox users, and if the application sets redirect: true
, which is false
by default.
References
CVSS Scores
version 3.1