GHSA-984p-xq9m-4rjw

Suggest an improvement
Source
https://github.com/advisories/GHSA-984p-xq9m-4rjw
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/06/GHSA-984p-xq9m-4rjw/GHSA-984p-xq9m-4rjw.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-984p-xq9m-4rjw
Published
2019-06-07T21:01:53Z
Modified
2021-08-04T21:03:16Z
Severity
  • 5.6 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L CVSS Calculator
Summary
Rate Limiting Bypass in express-brute
Details

All versions of express-brute are vulnerable to Rate Limiting Bypass. Concurrent requests may lead to race conditions that cause the package to incorrectly count requests. This may allow an attacker to bypass the rate limiting provided by the package and execute requests without limiting.

Recommendation

No fix is currently available. Consider using an alternative module until a fix is made available.

Database specific
{
    "cwe_ids":  [
        "CWE-77"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2019-06-07T21:01:37Z",
    "nvd_published_at":  null,
    "severity":  "MODERATE"
}
References

Affected packages

npm / express-brute

Package

Name
express-brute
View open source insights on deps.dev
Purl
pkg:npm/express-brute

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
1.0.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/06/GHSA-984p-xq9m-4rjw/GHSA-984p-xq9m-4rjw.json"