Junglewise Threat Intelligence

CVE-2024-43796: Express XSS via response.redirect()

CVE-2024-43796 · Severity: low · CVSS 3.1 · Published 2024-09-10

Technologies: Express.

Executive brief

Express is a popular web application framework for Node.js used to build web servers and APIs. A vulnerability in the response.redirect() function allows attackers to inject and execute malicious scripts in the browser if untrusted user input is passed to this function, even after sanitization. Exploitation requires specific conditions including user interaction (clicking a link), but successful attacks could lead to session hijacking, credential theft, or malware infection.

Technical details

A cross-site scripting (XSS) vulnerability exists in Express versions prior to 4.20.0 and 5.0.0-alpha.1 through 5.0.0-beta.x due to improper neutralization of user input in the response.redirect() function (CWE-79). The vulnerability allows an attacker controlling the redirect destination to inject arbitrary JavaScript code that executes in the user's browser. Exploitation requires multiple preconditions: the attacker must control the input to response.redirect(), Express must not complete the redirect before rendering a template, and the user must click on a link in that template. The fix was applied in Express 4.20.0 and 5.0.0, and users should upgrade to these patched versions immediately.

Affected products

  • Express Express <4.20.0, >=5.0.0-alpha.1 <5.0.0

Timeline

  • 2024-09-10: disclosed
  • 2024-09-10: patched: Express 4.20.0 and 5.0.0

References