GHSA-qmw8-3v4g-gwj4

    Dashboard / Vulnerabilities / GHSA-qmw8-3v4g-gwj4

    GHSA-qmw8-3v4g-gwj4

    Published: 3 Mar 2021Last Modified: 8 Jul 2026

    Summary: Prefix escape

    Details: ### Impact By crafting a specific URL, it is possible to escape the prefix of the proxied backend service. If the base url of the proxied server is `/pub/`, a user expect that accessing `/priv` on the target service would not be possible. Unfortunately, it is. [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N](https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N) ### Patches A patch have been submitted by Corey Farrell [email protected], the reporter. All releases after v4.0.2 include the fix. ### Workarounds There are no workaround available. ### For more information If you have any questions or comments about this advisory: * Open an issue in [fastify-reply-from](https://github.com/fastify/fastify-reply-from) * Email us at [[email protected]](mailto:[email protected])

    Affected packages

    Package

    Name: fastify-reply-from

    Purl: pkg:npm/fastify-reply-from

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -4.0.2

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-qmw8-3v4g-gwj4 | CVE-DB