OSV 1.4.0 · github-reviewed · 修改于 2021-10-21 23:01
发布时间
2021-10-06 04:24
GitHub 审查时间
2021-10-06 02:55
NVD 发布时间
2021-10-14 23:15
源文件
advisories/github-reviewed/2021/10/GHSA-p6vg-p826-qp3v/GHSA-p6vg-p826-qp3v.json
A redirect vulnerability in the fastify-static module allows remote attackers to redirect Mozilla Firefox users to arbitrary websites via a double slash // followed by a domain: http://localhost:3000//google.com/%2e%2e.
The issue shows up on all the fastify-static applications that set redirect: true option. By default, it is false.
The issue has been patched in [email protected]
If updating is not an option, you can sanitize the input URLs using the rewriteUrl server option.
If you have any questions or comments about this advisory: