Skip to content

VEX for CVE-2024-29409: nest allows a remote attacker to execute arbitrary code via the Content-Type header #144

@rainer-exxcellent

Description

@rainer-exxcellent

Dependabot has reported the following vulnerability
https://github.com/secvisogram/csaf-validator-service/security/dependabot/46

Csaf-validator-service is not affected by this vulnerability because it is only a transitive development dependency that is not delivered.
This is shown in the following VAX:

bsi-2025-0002.json

Metadata

Metadata

Labels

No labels
No labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions