CVE-2023-51701
Published: 08 January 2024
Summary
CVE-2023-51701 is a medium-severity HTTP Request/Response Smuggling (CWE-444) vulnerability in Fastify Reply-From. Its CVSS base score is 5.3 (Medium).
Operationally, ranked at the 45.8th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2024-0427
Vulnerability details
fastify-reply-from is a Fastify plugin to forward the current HTTP request to another server. A reverse proxy server built with `@fastify/reply-from` could misinterpret the incoming body by passing an header `ContentType: application/json ; charset=utf-8`. This can lead to bypass of…
more
security checks. This vulnerability has been patched in '@fastify/reply-from` version 9.6.0.
- CWE(s)
Related Threats
No named actor attribution yet. ATT&CK technique mapping in progress for this CVE.
Affected Assets
Mitigating Controls
No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.