PT-2019-20032 · Npm · Express-Brute
Published
2019-06-07
·
Updated
2019-06-07
CVSS v3.1
5.6
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
express-brute versions all
Description
The issue allows an attacker to bypass rate limiting, potentially executing requests without limitation, due to concurrent requests leading to race conditions that cause incorrect request counting.
Recommendations
For express-brute versions all, consider using an alternative module until a fix is made available.
Fix
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Express-Brute