CVE-2024-10491 describes a vulnerability in the Express response.links function, affecting openjsf express, where unsanitized data can lead to arbitrary resource injection in the Link header. This medium-severity vulnerability (CVSS 5.3) has a low impact on integrity, allowing attackers to preload malicious resources through improper sanitization of Link header values. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.0.0-alpha1, <= 3.21.2CPE match | cpe:2.3:a:express:express:*:*:*:*:*:android:*:* | ||
>= 3.0.0, < 3.21.5CPE matchmatch criteria | cpe:2.3:a:openjsf:express:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.