CVE-2021-22963

Related Vulnerabilities: CVE-2021-22963  

A redirect vulnerability in the fastify-static module version < 4.2.4 allows remote attackers to redirect users to arbitrary websites via a double slash // followed by a domain: http://localhost:3000//google.com/%2e%2e.The issue shows up on all the fastify-static applications that set redirect: true option. By default, it is false.

Description

The MITRE CVE dictionary describes this issue as:

A redirect vulnerability in the fastify-static module version < 4.2.4 allows remote attackers to redirect users to arbitrary websites via a double slash // followed by a domain: http://localhost:3000//google.com/%2e%2e.The issue shows up on all the fastify-static applications that set redirect: true option. By default, it is false.

Additional Information

  • Bugzilla 2015152: CVE-2021-22963 fastify-static: open redirect via an URL with double slash followed by a domain
  • CWE-601: URL Redirection to Untrusted Site ('Open Redirect')
  • FAQ: Frequently asked questions about CVE-2021-22963