Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2024-10491

A vulnerability has been identified in the Express response.links function, allowing for arbitrary resource injection in the Link header when unsanitized data is used. The issue arises from improper sanitization in `Link` header values, which can allow a combination of characters like `,`, `;`, and `<>` to preload malicious resources. This vulnerability is especially relevant for dynamic parameters.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 37.1%
CVSS Severity
CVSS v3 Score 4.0
Products affected by CVE-2024-10491
  • Openjsf » Express » Version: 3.0.0
    cpe:2.3:a:openjsf:express:3.0.0
  • Openjsf » Express » Version: 3.0.1
    cpe:2.3:a:openjsf:express:3.0.1
  • Openjsf » Express » Version: 3.0.2
    cpe:2.3:a:openjsf:express:3.0.2
  • Openjsf » Express » Version: 3.0.3
    cpe:2.3:a:openjsf:express:3.0.3
  • Openjsf » Express » Version: 3.0.4
    cpe:2.3:a:openjsf:express:3.0.4
  • Openjsf » Express » Version: 3.0.5
    cpe:2.3:a:openjsf:express:3.0.5
  • Openjsf » Express » Version: 3.0.6
    cpe:2.3:a:openjsf:express:3.0.6
  • Openjsf » Express » Version: 3.1.0
    cpe:2.3:a:openjsf:express:3.1.0
  • Openjsf » Express » Version: 3.1.1
    cpe:2.3:a:openjsf:express:3.1.1
  • Openjsf » Express » Version: 3.1.2
    cpe:2.3:a:openjsf:express:3.1.2
  • Openjsf » Express » Version: 3.10.0
    cpe:2.3:a:openjsf:express:3.10.0
  • Openjsf » Express » Version: 3.10.1
    cpe:2.3:a:openjsf:express:3.10.1
  • Openjsf » Express » Version: 3.10.2
    cpe:2.3:a:openjsf:express:3.10.2
  • Openjsf » Express » Version: 3.10.3
    cpe:2.3:a:openjsf:express:3.10.3
  • Openjsf » Express » Version: 3.10.4
    cpe:2.3:a:openjsf:express:3.10.4
  • Openjsf » Express » Version: 3.10.5
    cpe:2.3:a:openjsf:express:3.10.5
  • Openjsf » Express » Version: 3.11.0
    cpe:2.3:a:openjsf:express:3.11.0
  • Openjsf » Express » Version: 3.12.0
    cpe:2.3:a:openjsf:express:3.12.0
  • Openjsf » Express » Version: 3.12.1
    cpe:2.3:a:openjsf:express:3.12.1
  • Openjsf » Express » Version: 3.13.0
    cpe:2.3:a:openjsf:express:3.13.0
  • Openjsf » Express » Version: 3.14.0
    cpe:2.3:a:openjsf:express:3.14.0
  • Openjsf » Express » Version: 3.15.0
    cpe:2.3:a:openjsf:express:3.15.0
  • Openjsf » Express » Version: 3.15.1
    cpe:2.3:a:openjsf:express:3.15.1
  • Openjsf » Express » Version: 3.15.2
    cpe:2.3:a:openjsf:express:3.15.2
  • Openjsf » Express » Version: 3.15.3
    cpe:2.3:a:openjsf:express:3.15.3
  • Openjsf » Express » Version: 3.16.0
    cpe:2.3:a:openjsf:express:3.16.0
  • Openjsf » Express » Version: 3.16.1
    cpe:2.3:a:openjsf:express:3.16.1
  • Openjsf » Express » Version: 3.16.10
    cpe:2.3:a:openjsf:express:3.16.10
  • Openjsf » Express » Version: 3.16.2
    cpe:2.3:a:openjsf:express:3.16.2
  • Openjsf » Express » Version: 3.16.3
    cpe:2.3:a:openjsf:express:3.16.3
  • Openjsf » Express » Version: 3.16.4
    cpe:2.3:a:openjsf:express:3.16.4
  • Openjsf » Express » Version: 3.16.5
    cpe:2.3:a:openjsf:express:3.16.5
  • Openjsf » Express » Version: 3.16.6
    cpe:2.3:a:openjsf:express:3.16.6
  • Openjsf » Express » Version: 3.16.7
    cpe:2.3:a:openjsf:express:3.16.7
  • Openjsf » Express » Version: 3.16.8
    cpe:2.3:a:openjsf:express:3.16.8
  • Openjsf » Express » Version: 3.16.9
    cpe:2.3:a:openjsf:express:3.16.9
  • Openjsf » Express » Version: 3.17.0
    cpe:2.3:a:openjsf:express:3.17.0
  • Openjsf » Express » Version: 3.17.1
    cpe:2.3:a:openjsf:express:3.17.1
  • Openjsf » Express » Version: 3.17.2
    cpe:2.3:a:openjsf:express:3.17.2
  • Openjsf » Express » Version: 3.17.3
    cpe:2.3:a:openjsf:express:3.17.3
  • Openjsf » Express » Version: 3.17.4
    cpe:2.3:a:openjsf:express:3.17.4
  • Openjsf » Express » Version: 3.17.5
    cpe:2.3:a:openjsf:express:3.17.5
  • Openjsf » Express » Version: 3.17.6
    cpe:2.3:a:openjsf:express:3.17.6
  • Openjsf » Express » Version: 3.17.7
    cpe:2.3:a:openjsf:express:3.17.7
  • Openjsf » Express » Version: 3.17.8
    cpe:2.3:a:openjsf:express:3.17.8
  • Openjsf » Express » Version: 3.18.0
    cpe:2.3:a:openjsf:express:3.18.0
  • Openjsf » Express » Version: 3.18.1
    cpe:2.3:a:openjsf:express:3.18.1
  • Openjsf » Express » Version: 3.18.2
    cpe:2.3:a:openjsf:express:3.18.2
  • Openjsf » Express » Version: 3.18.3
    cpe:2.3:a:openjsf:express:3.18.3
  • Openjsf » Express » Version: 3.18.4
    cpe:2.3:a:openjsf:express:3.18.4
  • Openjsf » Express » Version: 3.18.5
    cpe:2.3:a:openjsf:express:3.18.5
  • Openjsf » Express » Version: 3.18.6
    cpe:2.3:a:openjsf:express:3.18.6
  • Openjsf » Express » Version: 3.19.0
    cpe:2.3:a:openjsf:express:3.19.0
  • Openjsf » Express » Version: 3.19.1
    cpe:2.3:a:openjsf:express:3.19.1
  • Openjsf » Express » Version: 3.19.2
    cpe:2.3:a:openjsf:express:3.19.2
  • Openjsf » Express » Version: 3.2.0
    cpe:2.3:a:openjsf:express:3.2.0
  • Openjsf » Express » Version: 3.2.1
    cpe:2.3:a:openjsf:express:3.2.1
  • Openjsf » Express » Version: 3.2.2
    cpe:2.3:a:openjsf:express:3.2.2
  • Openjsf » Express » Version: 3.2.3
    cpe:2.3:a:openjsf:express:3.2.3
  • Openjsf » Express » Version: 3.2.4
    cpe:2.3:a:openjsf:express:3.2.4
  • Openjsf » Express » Version: 3.2.5
    cpe:2.3:a:openjsf:express:3.2.5
  • Openjsf » Express » Version: 3.2.6
    cpe:2.3:a:openjsf:express:3.2.6
  • Openjsf » Express » Version: 3.20.0
    cpe:2.3:a:openjsf:express:3.20.0
  • Openjsf » Express » Version: 3.20.1
    cpe:2.3:a:openjsf:express:3.20.1
  • Openjsf » Express » Version: 3.20.2
    cpe:2.3:a:openjsf:express:3.20.2
  • Openjsf » Express » Version: 3.20.3
    cpe:2.3:a:openjsf:express:3.20.3
  • Openjsf » Express » Version: 3.21.0
    cpe:2.3:a:openjsf:express:3.21.0
  • Openjsf » Express » Version: 3.21.1
    cpe:2.3:a:openjsf:express:3.21.1
  • Openjsf » Express » Version: 3.21.2
    cpe:2.3:a:openjsf:express:3.21.2
  • Openjsf » Express » Version: 3.3.0
    cpe:2.3:a:openjsf:express:3.3.0
  • Openjsf » Express » Version: 3.3.1
    cpe:2.3:a:openjsf:express:3.3.1
  • Openjsf » Express » Version: 3.3.2
    cpe:2.3:a:openjsf:express:3.3.2
  • Openjsf » Express » Version: 3.3.3
    cpe:2.3:a:openjsf:express:3.3.3
  • Openjsf » Express » Version: 3.3.4
    cpe:2.3:a:openjsf:express:3.3.4
  • Openjsf » Express » Version: 3.3.5
    cpe:2.3:a:openjsf:express:3.3.5
  • Openjsf » Express » Version: 3.3.6
    cpe:2.3:a:openjsf:express:3.3.6
  • Openjsf » Express » Version: 3.3.7
    cpe:2.3:a:openjsf:express:3.3.7
  • Openjsf » Express » Version: 3.3.8
    cpe:2.3:a:openjsf:express:3.3.8
  • Openjsf » Express » Version: 3.4.0
    cpe:2.3:a:openjsf:express:3.4.0
  • Openjsf » Express » Version: 3.4.1
    cpe:2.3:a:openjsf:express:3.4.1
  • Openjsf » Express » Version: 3.4.2
    cpe:2.3:a:openjsf:express:3.4.2
  • Openjsf » Express » Version: 3.4.3
    cpe:2.3:a:openjsf:express:3.4.3
  • Openjsf » Express » Version: 3.4.4
    cpe:2.3:a:openjsf:express:3.4.4
  • Openjsf » Express » Version: 3.4.5
    cpe:2.3:a:openjsf:express:3.4.5
  • Openjsf » Express » Version: 3.4.6
    cpe:2.3:a:openjsf:express:3.4.6
  • Openjsf » Express » Version: 3.4.7
    cpe:2.3:a:openjsf:express:3.4.7
  • Openjsf » Express » Version: 3.4.8
    cpe:2.3:a:openjsf:express:3.4.8
  • Openjsf » Express » Version: 3.5.0
    cpe:2.3:a:openjsf:express:3.5.0
  • Openjsf » Express » Version: 3.5.1
    cpe:2.3:a:openjsf:express:3.5.1
  • Openjsf » Express » Version: 3.5.2
    cpe:2.3:a:openjsf:express:3.5.2
  • Openjsf » Express » Version: 3.5.3
    cpe:2.3:a:openjsf:express:3.5.3
  • Openjsf » Express » Version: 3.6.0
    cpe:2.3:a:openjsf:express:3.6.0
  • Openjsf » Express » Version: 3.7.0
    cpe:2.3:a:openjsf:express:3.7.0
  • Openjsf » Express » Version: 3.8.0
    cpe:2.3:a:openjsf:express:3.8.0
  • Openjsf » Express » Version: 3.8.1
    cpe:2.3:a:openjsf:express:3.8.1
  • Openjsf » Express » Version: 3.9.0
    cpe:2.3:a:openjsf:express:3.9.0


Contact Us

Shodan ® - All rights reserved