Junglewise Threat Intelligence

CVE-2022-29622: Formidable arbitrary file upload via crafted filename

CVE-2022-29622 · Severity: low · CVSS 3.1 · Published 2022-05-17

Vendors: npm, Formidable.

Executive brief

Formidable is a popular Node.js library for handling file uploads in web applications. An arbitrary file upload vulnerability allows attackers to bypass upload restrictions by crafting malicious filenames, potentially leading to arbitrary code execution on servers using the vulnerable version.

Technical details

This is an arbitrary file upload vulnerability (CWE-434) in Formidable versions prior to 3.2.4, where attackers can exploit insufficient filename validation to upload files bypassing security checks. The vulnerability requires network access to upload functionality and no special privileges or user interaction. By crafting a malicious filename, an attacker can upload arbitrary files to the server, potentially achieving arbitrary code execution depending on server configuration and application logic. A patch is available in version 3.2.4 or later.

Affected products

  • formidable formidable before 3.2.4

Timeline

  • 2022-05-17: disclosed
  • 2024-04-25: other: Advisory withdrawn as improperly assigned

References