CVE-2023-51701
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Jan 8, 2024
Updated: Jan 11, 2024
CWE ID 444
Summary
CVE-2023-51701 is a vulnerability affecting the Fastify plugin "fastify-reply-from". This plugin is used to forward HTTP requests to another server in Fastify applications. An issue arises when a reverse proxy server, constructed using `@fastify/reply-from`, receives an incorrectly formatted header. Specifically, if the header contains "ContentType: application/json ; charset=utf-8", the server may misinterpret the incoming body, potentially bypassing security checks. This issue has been addressed in version 9.6.0 of the plugin.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- Fastify