漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
@fastify/middie vulnerable to middleware bypass via deprecated ignoreDuplicateSlashes option
Vulnerability Description
@fastify/middie versions 9.3.1 and earlier are vulnerable to middleware bypass when the deprecated Fastify ignoreDuplicateSlashes option is enabled. The middleware path matching logic does not account for duplicate slash normalization performed by Fastify's router, allowing requests with duplicate slashes to bypass middleware authentication and authorization checks. This only affects applications using the deprecated ignoreDuplicateSlashes option. Upgrade to @fastify/middie 9.3.2 to fix this issue. There are no workarounds other than disabling the ignoreDuplicateSlashes option.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Vulnerability Type
解释冲突
Vulnerability Title
@fastify/middie 安全漏洞
Vulnerability Description
@fastify/middie是Fastify开源的一个中间件引擎。 @fastify/middie 9.3.1及之前版本存在安全漏洞,该漏洞源于当启用已弃用的ignoreDuplicateSlashes选项时,中间件路径匹配逻辑未考虑Fastify路由器的重复斜杠规范化,可能导致带有重复斜杠的请求绕过中间件身份验证和授权检查。
CVSS Information
N/A
Vulnerability Type
N/A