Vulnerabilities
Vulnerable Software
Expressjs:  Security Vulnerabilities
basic-auth-connect is Connect's Basic Auth middleware in its own module. basic-auth-connect < 1.1.0 uses a timing-unsafe equality comparison that can leak timing information. This issue has been fixed in basic-auth-connect 1.1.0.
CVSS Score
5.3
EPSS Score
0.002
Published
2024-09-30
method-override is a module used by the Express.js framework to let you use HTTP verbs such as PUT or DELETE in places where the client doesn't support it. method-override is vulnerable to a regular expression denial of service vulnerability when specially crafted input is passed in to be parsed via the X-HTTP-Method-Override header.
CVSS Score
7.5
EPSS Score
0.003
Published
2018-06-07


Contact Us

Shodan ® - All rights reserved