CVE-2024-57177
CVSS 3.1 Score 7.3 of 10 (high)
Details
Published Feb 10, 2025
CWE ID 74
Summary
CVE-2024-57177: A critical vulnerability has been identified in the perfood/couch-auth NPM package versions prior to 0.21.2. Hackers can exploit a host header injection flaw to execute a Server-Side Template Injection (SSTI) attack. By manipulating the host header in an email change confirmation request, they can run limited commands or gain access to sensitive server-side data. This vulnerability poses a significant threat to applications using the affected NPM package and necessitates an immediate update.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share