Web Cache Poisoning Affecting find-my-way package, versions <2.2.5 >=3.0.0 <3.0.5
Threat Intelligence
Exploit Maturity
Proof of concept
EPSS
0.11% (45th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-JS-FINDMYWAY-1038269
- published 8 Nov 2020
- disclosed 3 Nov 2020
- credit yousteen, trygve_lie
Introduced: 3 Nov 2020
CVE-2020-7764 Open this link in a new tabHow to fix?
Upgrade find-my-way
to version 2.2.5, 3.0.5 or higher.
Overview
Affected versions of this package are vulnerable to Web Cache Poisoning. It accepts the Accept-Version
header by default, and if versioned routes are not being used, this could lead to a denial of service. Accept-Version
can be used as an unkeyed header in a cache poisoning attack.
CVSS Scores
version 3.1