VulnerabilityDeferred
CVE-2024-9266
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Express.
MEDIUM 4.7EPSS 0.46%
Does this matter?
Lower severity and a low EPSS score (0.46%). Track it; it rarely justifies an emergency change on its own.
Description
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Express. This vulnerability affects the use of the Express Response object. This issue impacts Express: from 3.4.5 before 4.0.0.
- CVSS 3.1
- 4.7 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N
- EPSS
- 0.46% probability · 39th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-601
- Source
- 36c7be3b-2937-45df-85ea-ca7133ea542c
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.