Vulnerability Details CVE-2021-23384
The package koa-remove-trailing-slashes before 2.0.2 are vulnerable to Open Redirect via the use of trailing double slashes in the URL when accessing the vulnerable endpoint (such as https://example.com//attacker.example/). The vulnerable code is in index.js::removeTrailingSlashes(), as the web server uses relative URLs instead of absolute URLs.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 43.3%
CVSS Severity
CVSS v3 Score 5.4
CVSS v2 Score 5.8
Products affected by CVE-2021-23384
-
cpe:2.3:a:koa-remove-trailing-slashes_project:koa-remove-trailing-slashes:-
-
cpe:2.3:a:koa-remove-trailing-slashes_project:koa-remove-trailing-slashes:1.0.0
-
cpe:2.3:a:koa-remove-trailing-slashes_project:koa-remove-trailing-slashes:2.0.0
-
cpe:2.3:a:koa-remove-trailing-slashes_project:koa-remove-trailing-slashes:2.0.1