Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Krynos

Researcher fromErcoli Consulting
#36387of 53,632
7.5Total CVSS
Vulnerabilities · 1
PT-2022-16902
7.5
2022-04-06
Unknown · @Podium/Proxy · CVE-2022-24822
**Name of the Vulnerable Software and Affected Versions** @podium/layout versions prior to 4.6.110 @podium/proxy versions prior to 4.2.74 **Description** The issue allows an attacker to take down the server by using the `Trailer` header as part of the request against proxy endpoints. All Podium layouts that include podlets with proxy endpoints are affected. **Recommendations** For @podium/layout versions prior to 4.6.110, upgrade to version 4.6.110 or later. For @podium/proxy versions prior to 4.2.74, upgrade to version 4.2.74 or later. As a temporary workaround is not easily possible without upgrading, it is recommended to upgrade @podium/layout and/or @podium/proxy as soon as possible.