Executive brief
express-param is a Node.js library used to parse HTTP request parameters in Express applications. A vulnerability in versions prior to 1.0.0 allows attackers to manipulate request parameters in ways that bypass intended filtering logic, potentially leading to data exposure, application logic bypass, or denial of service. The flaw affects how the library handles extra or malformed parameters in incoming HTTP requests.
Technical details
The vulnerability exists in lib/fetchParams.js and involves improper handling of extra parameters (CWE-235), making it susceptible to HTTP Parameter Pollution (HPP) attacks. The flaw allows attackers to inject or manipulate additional parameters in requests without proper validation or sanitization. An attacker can remotely exploit this vulnerability without authentication or user interaction by sending specially crafted HTTP requests with malicious parameter combinations. The patch (version 1.0.0, commit db94f7391ad0a16dcfcba8b9be1af385b25c42db) implements geo-info tracking in extra options and protective measures against parameter pollution attacks. Users should upgrade to version 1.0.0 or later.
Affected products
- flitto express-param all versions prior to 1.0.0
Timeline
- 2022-12-31: disclosed
- 2017-03-07: patched: PR #19 merged with patch commit db94f7391ad0a16dcfcba8b9be1af385b25c42db; version 1.0.0 released