7.7 HIGH
- CVSS version (CVSS): 4.0
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Attack Requirement (AT): None (N)
- Privileges Required (PR): None (N)
- User Interaction (UI): None (N)
- Vulnerable System Impact Confidentiality (VC): None (N)
- Vulnerable System Impact Integrity (VI): Low (L)
- Vulnerable System Impact Availability (VA): None (N)
- Subsequent System Impact Confidentiality (SC): None (N)
- Subsequent System Impact Integrity (SI): High (H)
- Subsequent System Impact Availability (SA): None (N)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Attack Requirement (MAT): None (N)
- Modified Privileges Required (MPR): None (N)
- Modified User Interaction (MUI): None (N)
- Modified Vulnerable System Impact Confidentiality (MVC): None (N)
- Modified Vulnerable System Impact Integrity (MVI): Low (L)
- Modified Vulnerable System Impact Availability (MVA): None (N)
- Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
- Modified Subsequent System Impact Integrity (MSI): High (H)
- Modified Subsequent System Impact Availability (MSA): Negligible (N)
- Safety (S): Not Defined (X)
- Automatable (AU): Not Defined (X)
- Recovery (R): Not Defined (X)
- Value Density (V): Not Defined (X)
- Vulnerability Response Effort (RE): Not Defined (X)
- Provider Urgency (U): Not Defined (X)
- Confidentiality Req. (CR): Not Defined (X)
- Integrity Req. (IR): Not Defined (X)
- Availability Req. (AR): Not Defined (X)
- Exploit Maturity (E): Not Defined (X)
Activity log
- Created suggestion
Parameter smuggling in @hapi/content header parser allows upload-filter bypass via duplicate parameters
@hapi/content provided HTTP Content-* headers parsing. Prior to 6.0.2, Content.disposition() retained the last occurrence of each duplicate parameter while Content.type() retained the first occurrence of duplicate charset and boundary parameters, creating a parameter-smuggling primitive when another component in the request-processing chain resolves duplicates the opposite way. This can allow an upload filename allowlist bypass in headers such as Content-Disposition: form-data; name="file"; filename="safe.txt"; filename="shell.php". This issue is fixed in version 6.0.2.
References
Affected products
- ==< 6.0.2
Matching in nixpkgs
pkgs.malcontent
Parental controls library
pkgs.jazz2-content
Assets needed for jazz2
pkgs.malcontent-ui
UI components for parental controls library
pkgs.lomiri.content-hub
Content sharing/picking service for the Lomiri desktop
pkgs.local-content-share
Storing/sharing text/files in your local network with no setup on client devices
pkgs.lomiri.lomiri-content-hub
Content sharing/picking service for the Lomiri desktop
pkgs.lomiri-qt6.lomiri-content-hub
Content sharing/picking service for the Lomiri desktop
pkgs.perlPackages.TestFileContents
Test routines for examining the contents of files
pkgs.perl5Packages.TestFileContents
Test routines for examining the contents of files
pkgs.perlPackages.EmailMIMEContentType
Parse and build a MIME Content-Type or Content-Disposition Header
pkgs.haskellPackages.directory-contents
Recursively build, navigate, and operate on a tree of directory contents
pkgs.perl5Packages.EmailMIMEContentType
Parse and build a MIME Content-Type or Content-Disposition Header
pkgs.python313Packages.zope-contenttype
Utility module for content-type (MIME type) handling
pkgs.python314Packages.zope-contenttype
Utility module for content-type (MIME type) handling
pkgs.haskellPackages.pdf-toolbox-content
A collection of tools for processing PDF files
pkgs.haskellPackages.servant-fiat-content
Fiat content types
pkgs.ocamlPackages.content_security_policy
Library for building content-security policies
pkgs.haskellPackages.gogol-shopping-content
Google Content API for Shopping SDK
pkgs.ocamlPackages_latest.content_security_policy
Library for building content-security policies
pkgs.ocamlPackages.janeStreet.content_security_policy
Library for building content-security policies
Package maintainers
-
@e-v-o-l-v-e Ivanoe Megnin-Preiss <oss@imp-network.com>
-
@OPNA2608 Cosima Neidahl <opna2608@protonmail.com>
-
@jtojnar Jan Tojnar <jtojnar@gmail.com>