CVE-2024-57177 - "Couch-Auth Host Header Injection SSTI Vulnerability"
CVE ID : CVE-2024-57177
Published : Feb. 10, 2025, 8:15 p.m. | 2 hours, 15 minutes ago
Description : A host header injection vulnerability exists in the NPM package of perfood/couch-auth <= 0.21.2. By sending a specially crafted host header in the email change confirmation request, it is possible to trigger a SSTI which can be leveraged to run limited commands or leak server-side information
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Feb. 10, 2025, 8:15 p.m. | 2 hours, 15 minutes ago
Description : A host header injection vulnerability exists in the NPM package of perfood/couch-auth <= 0.21.2. By sending a specially crafted host header in the email change confirmation request, it is possible to trigger a SSTI which can be leveraged to run limited commands or leak server-side information
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...