Vulnerabilities/

method-override ReDoS when untrusted user input passed into X-HTTP-Method-Override header

Severity:
High

Description

Affected versions of method-override are vulnerable to a regular expression denial of service vulnerability when untrusted user input is passed into the X-HTTP-Method-Override header.

Recommendation

Update the method-override package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
method-override
Anything's wrong? Let us know Last updated on September 11, 2023

This issue is available in SmartScanner Professional

See Pricing