DirectorySecurity Advisories
Sign In
Security Advisories

CGA-fh9q-m32j-c356

Published

Last updated

https://images.chainguard.dev/security/CGA-fh9q-m32j-c356
Package

kubeflow-centraldashboard

Latest Update
Fixed
Fixed Version

1.9.0-r4

Aliases
  • CVE-2024-45590
  • GHSA-qwcr-r2fm-qrc7

Severity

7.5

High

CVSS V3

Summary

body-parser vulnerable to denial of service when url encoding is enabled

Description

Impact

body-parser <1.20.3 is vulnerable to denial of service when url encoding is enabled. A malicious actor using a specially crafted payload could flood the server with a large number of requests, resulting in denial of service.

Patches

this issue is patched in 1.20.3

References

References

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images