CVE-2024-49770

`oak` is a middleware framework for Deno's native HTTP server, Deno Deploy, Node.js 16.5 and later, Cloudflare Workers and Bun. By default `oak` does not allow transferring of hidden files with `Context.send` API. However, prior to version 17.1.3, this can be bypassed by encoding `/` as its URL encoded form `%2F`. For an attacker this has potential to read sensitive user data or to gain access to server secrets. Version 17.1.3 fixes the issue.
CVSS

No CVSS.

Configurations

No configuration.

History

01 Nov 2024, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-01 17:15

Updated : 2024-11-01 20:24


NVD link : CVE-2024-49770

Mitre link : CVE-2024-49770

CVE.ORG link : CVE-2024-49770


JSON object : View

Products Affected

No product.

CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CWE-35

Path Traversal: '.../...//'