Executive brief
The Bare Server Node package is a proxy server library used to relay and modify HTTP traffic. This vulnerability allows attackers to manipulate web traffic passing through systems using this library, potentially exposing or altering sensitive data. Organizations using this package in production should upgrade immediately to mitigate exposure of intercepted communications.
Technical details
This is an HTTP request handling vulnerability (CWE-444) in @tomphttp/bare-server-node that allows insecure processing of HTTP requests. The vulnerability is network-exploitable with no authentication or user interaction required, affecting all versions prior to 2.0.2. An unauthenticated remote attacker can exploit this flaw to manipulate web traffic with high impact on confidentiality, integrity, and availability. A patch is available in version 2.0.2 and users should upgrade immediately; detailed exploitation techniques are being withheld to allow time for patches to deploy.
Affected products
- tomphttp Bare Server Node <2.0.2
Timeline
- 2024-03-05: disclosed: GHSA published
- 2024-03-05: patched: Version 2.0.2 released with fix