CVE-2024-27922

Source
https://cve.org/CVERecord?id=CVE-2024-27922
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-27922.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-27922
Aliases
Published
2024-03-06T20:33:57.922Z
Modified
2026-03-14T12:27:55.501209Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
HTTP Handling Vulnerability in the Bare server
Details

TOMP Bare Server implements the TompHTTP bare server. A vulnerability in versions prior to 2.0.2 relates to insecure handling of HTTP requests by the @tomphttp/bare-server-node package. This flaw potentially exposes the users of the package to manipulation of their web traffic. The impact may vary depending on the specific usage of the package but it can potentially affect any system where this package is in use. The problem has been patched in version 2.0.2. As of time of publication, no specific workaround strategies have been disclosed.

Database specific
{
    "cwe_ids": [
        "CWE-444"
    ],
    "cna_assigner": "GitHub_M",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/27xxx/CVE-2024-27922.json"
}
References

Affected packages

Git / github.com/tomphttp/bare-server-node

Affected ranges

Type
GIT
Repo
https://github.com/tomphttp/bare-server-node
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

v1.*
v1.0.0-beta
v1.0.0-beta-readme1
v1.0.1-beta
v1.0.1-beta-readme1
v1.0.2-beta
v1.0.2-beta-readme2
v1.0.2-beta-readme4
v1.0.2-beta-readme5
v1.0.2-beta-rollup1
v1.0.2-beta-typings3
v1.0.3
v1.0.3-deps2
v1.0.3-log1
v1.0.4
v1.0.4-deps1
v1.1.0
v1.2.1
v1.2.2
v1.2.3
v1.2.5
v1.2.6
v2.*
v2.0.0
v2.0.0-beta
v2.0.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-27922.json"