PT-2019-20032 · Npm · Express-Brute

Published

2019-06-07

·

Updated

2019-06-07

CVSS v3.1

5.6

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions express-brute versions all
Description The issue allows an attacker to bypass rate limiting, potentially executing requests without limitation, due to concurrent requests leading to race conditions that cause incorrect request counting.
Recommendations For express-brute versions all, consider using an alternative module until a fix is made available.

Fix

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

GHSA-984P-XQ9M-4RJW

Affected Products

Express-Brute