HIGH
Web Cache Poisoning
Published Nov 8, 2020
7.5
HIGHCVSS 3.1
EPSS 1.73%
Description
This affects the package find-my-way before 2.2.5, from 3.0.0 and before 3.0.5. It accepts the Accept-Version' header by default, and if versioned routes are not being used, this could lead to a denial of service. Accept-Version can be used as an unkeyed header in a cache poisoning attack.
Affected products
- Vendor n/a Product Find-MY-Way Defaultn/a
- Version 3.0.0StatusaffectedConstraints<unspecified
- Version unspecifiedStatusaffectedConstraints<2.2.5
- Version unspecifiedStatusaffectedConstraints<3.0.5
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| n/a | Find-MY-Way | n/a |
|
OR
- < 2.2.5
- ≥ 3.0.0 · < 3.0.5
No data.
No Red Hat product state for this CVE.
find-my-way
npm
Introduced 0 Fixed 2.2.5find-my-way
npm
Introduced 3.0.0 Fixed 3.0.5
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | find-my-way | 0 | 2.2.5 |
| npm | find-my-way | 3.0.0 | 3.0.5 |
Remediation
No remediation recorded yet.
Weaknesses (1)
References (5)
- https://github.com/advisories/GHSA-jgrh-5m3h-9c5f Advisory
- https://github.com/delvedor/find-my-way/commit/ab408354690e6b9cf3c4724befb3b3fa4bb90aac x_refsource_MISCPatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2020-7764
- https://snyk.io/vuln/SNYK-JS-FINDMYWAY-1038269 x_refsource_MISCThird Party Advisory
- https://www.npmjs.com/package/find-my-way
| Link | Providers | Tags |
|---|---|---|
| https://github.com/advisories/GHSA-jgrh-5m3h-9c5f | Advisory | |
| https://github.com/delvedor/find-my-way/commit/ab408354690e6b9cf3c4724befb3b3fa4bb90aac | x_refsource_MISCPatchThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2020-7764 | ||
| https://snyk.io/vuln/SNYK-JS-FINDMYWAY-1038269 | x_refsource_MISCThird Party Advisory | |
| https://www.npmjs.com/package/find-my-way |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner snyk
Published Nov 8, 2020
Updated Sep 17, 2024
Reserved Jan 21, 2020
Link CVE-2020-7764
CISA Vulnrichment
GHSA-JGRH-5M3H-9C5F Updated n/a